ZDI-26-099: Oracle VirtualBox VMSVGA Race Condition Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-21984.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-099?
ZDI-26-099 is considered a high-severity vulnerability due to its potential for local privilege escalation.
How do I fix ZDI-26-099?
To resolve ZDI-26-099, update Oracle VirtualBox to the latest version provided by Oracle that addresses this vulnerability.
Who is affected by ZDI-26-099?
ZDI-26-099 affects users of Oracle VirtualBox who have installed the software on their systems.
What type of attacks are possible with ZDI-26-099?
ZDI-26-099 allows local attackers to escalate their privileges, potentially gaining higher access on the affected system.
Is there a workaround for ZDI-26-099?
Currently, the recommended course of action for ZDI-26-099 is to apply the official update from Oracle, as workarounds may not fully mitigate the vulnerability.