ZDI-CAN-28080: ZDI-26-101: Oracle VirtualBox BusLogic Uninitialized Memory Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.0. The following CVEs are assigned: CVE-2026-21963.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28080?
The severity of ZDI-CAN-28080 is classified as a medium risk due to its potential for information disclosure.
How do I fix ZDI-CAN-28080?
To fix ZDI-CAN-28080, update Oracle VirtualBox to the latest version that includes security patches addressing this vulnerability.
What can an attacker achieve with ZDI-CAN-28080?
An attacker exploiting ZDI-CAN-28080 can disclose sensitive information from affected installations of Oracle VirtualBox.
What versions of Oracle VirtualBox are affected by ZDI-CAN-28080?
ZDI-CAN-28080 affects all versions of Oracle VirtualBox prior to the security updates that mitigate this vulnerability.
Is remote access required to exploit ZDI-CAN-28080?
No, ZDI-CAN-28080 requires local access to the affected system as it necessitates high-privileged code execution.