ZDI-CAN-27938: ZDI-26-102: Oracle VirtualBox VMSVGA Out-Of-Bounds Write Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-21957.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-27938?
The severity of ZDI-CAN-27938 is critical due to its ability to allow local privilege escalation on affected Oracle VirtualBox installations.
How do I fix ZDI-CAN-27938?
To fix ZDI-CAN-27938, users should update their Oracle VirtualBox to the latest version provided by Oracle that addresses this vulnerability.
Who is affected by ZDI-CAN-27938?
Users of Oracle VirtualBox are affected by ZDI-CAN-27938 if they have not applied the latest security patches.
What type of attack does ZDI-CAN-27938 enable?
ZDI-CAN-27938 enables local privilege escalation attacks, allowing attackers to gain higher privileges on a compromised system.
Is ZDI-CAN-27938 being exploited in the wild?
There is currently no public information indicating that ZDI-CAN-27938 is being actively exploited in the wild.