ZDI-26-103: Oracle VirtualBox VMSVGA Out-Of-Bounds Access Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2026-21956.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-103?
The severity of ZDI-26-103 is high, as it allows local attackers to escalate their privileges.
How do I fix ZDI-26-103?
To fix ZDI-26-103, update your Oracle VirtualBox to the latest version provided by Oracle.
What causes the ZDI-26-103 vulnerability?
ZDI-26-103 is caused by an out-of-bounds access vulnerability in the VMSVGA component of Oracle VirtualBox.
Can ZDI-26-103 be exploited remotely?
No, ZDI-26-103 requires local access to the target guest system to exploit the vulnerability.
What are the potential impacts of ZDI-26-103?
The potential impacts of ZDI-26-103 include unauthorized privilege escalation, which can lead to full control over the affected system.