ZDI-CAN-30184: ZDI-26-639: Oracle VirtualBox VMSVGA Heap-based Buffer Overflow Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-71116.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need before exploiting this issue?
The attacker must already be able to execute high-privileged code on the target guest system. The provided information does not describe exploitation by an unprivileged guest user or from the host without that prerequisite.
Where does the privilege escalation occur?
The vulnerability is described as allowing local attackers to escalate privileges on affected Oracle VirtualBox installations, with the prerequisite code execution occurring on the target guest system. The issue involves a heap-based buffer overflow in the VMSVGA component.