ZDI-26-102: Oracle VirtualBox VMSVGA Out-Of-Bounds Write Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-21957.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-102?
The severity of ZDI-26-102 is classified as critical due to the potential for privilege escalation.
How do I fix ZDI-26-102?
To fix ZDI-26-102, you should update Oracle VirtualBox to the latest version that addresses this vulnerability.
What systems are affected by ZDI-26-102?
ZDI-26-102 affects installations of Oracle VirtualBox that are running on systems where high-privileged code execution is possible.
Who can exploit ZDI-26-102?
ZDI-26-102 can be exploited by local attackers who have already gained the ability to execute code on the guest system.
What is the potential impact of ZDI-26-102?
The potential impact of ZDI-26-102 is local privilege escalation, allowing attackers to gain higher-level access on affected systems.