ZDI-CAN-28045: ZDI-26-097: Oracle VirtualBox VMSVGA Heap-based Buffer Overflow Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-21983.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28045?
The severity of ZDI-CAN-28045 is classified as critical due to its potential for local privilege escalation.
How do I fix ZDI-CAN-28045?
To fix ZDI-CAN-28045, update Oracle VirtualBox to the latest version provided by Oracle that addresses this vulnerability.
What products are affected by ZDI-CAN-28045?
ZDI-CAN-28045 affects installations of Oracle VirtualBox software.
Who can exploit ZDI-CAN-28045?
Local attackers with the ability to execute high-privileged code can exploit ZDI-CAN-28045 to gain elevated privileges.
What type of vulnerability is ZDI-CAN-28045?
ZDI-CAN-28045 is a heap-based buffer overflow vulnerability leading to local privilege escalation.