ZDI-26-362: Oracle VirtualBox VMSVGA Stack-based Buffer Overflow Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-46873.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-362?
The severity of ZDI-26-362 is rated at 7.5 according to CVSS.
How do I fix ZDI-26-362?
To fix ZDI-26-362, update Oracle VirtualBox to the latest version that addresses this vulnerability.
What type of attack does ZDI-26-362 represent?
ZDI-26-362 represents a local privilege escalation vulnerability due to a stack-based buffer overflow.
Who can exploit ZDI-26-362?
Local attackers with high-privileged code execution on the guest system can exploit ZDI-26-362.
Which software is affected by ZDI-26-362?
Oracle VirtualBox is the affected software for the ZDI-26-362 vulnerability.