ZDI-CAN-27870: ZDI-26-098: Oracle VirtualBox VMSVGA Use-After-Free Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2026-21955.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-27870?
The severity of ZDI-CAN-27870 is high due to its potential for local privilege escalation.
How do I fix ZDI-CAN-27870?
To fix ZDI-CAN-27870, apply the latest security patches provided by Oracle for VirtualBox.
Who is affected by ZDI-CAN-27870?
Users of Oracle VirtualBox installations are affected by ZDI-CAN-27870.
What type of vulnerability is ZDI-CAN-27870?
ZDI-CAN-27870 is a use-after-free vulnerability that can lead to local privilege escalation.
What must an attacker do to exploit ZDI-CAN-27870?
To exploit ZDI-CAN-27870, an attacker must have the ability to execute high-privileged code on the target guest.