ZDI-CAN-27923: ZDI-26-103: Oracle VirtualBox VMSVGA Out-Of-Bounds Access Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2026-21956.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-27923?
The severity of ZDI-CAN-27923 is high due to its potential for local privilege escalation.
How do I fix ZDI-CAN-27923?
To fix ZDI-CAN-27923, update your Oracle VirtualBox installation to the latest version provided by Oracle.
Who is affected by ZDI-CAN-27923?
ZDI-CAN-27923 affects users of Oracle VirtualBox installations that have not been updated.
What kind of attacks can ZDI-CAN-27923 enable?
ZDI-CAN-27923 can enable local attackers to escalate their privileges on affected systems.
Is ZDI-CAN-27923 a remote or local vulnerability?
ZDI-CAN-27923 is a local vulnerability, requiring attackers to have access to execute code on the target system.