ZDI-26-098: Oracle VirtualBox VMSVGA Use-After-Free Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2026-21955.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-098?
The severity of ZDI-26-098 is categorized as high due to its potential to allow local privilege escalation.
How do I fix ZDI-26-098?
To fix ZDI-26-098, users should update their Oracle VirtualBox installation to the latest version that addresses this vulnerability.
Who is affected by ZDI-26-098?
ZDI-26-098 affects users of Oracle VirtualBox who have not applied the necessary security updates.
Can ZDI-26-098 be exploited remotely?
No, ZDI-26-098 requires local access to the affected system to exploit the vulnerability.
What type of vulnerability is ZDI-26-098?
ZDI-26-098 is classified as a use-after-free vulnerability leading to local privilege escalation.