ZDI-26-642: Oracle VirtualBox IDisplay Out-Of-Bounds Read Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-60159.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need before exploiting this issue?
The attacker must already be able to execute high-privileged code on the target guest system. The issue is therefore relevant to environments where a guest compromise has already provided privileged execution.
Where does the privilege escalation occur?
The vulnerability affects Oracle VirtualBox through its IDisplay component and can allow a local attacker to escalate privileges on an affected installation. The supplied information does not identify affected versions or configurations.