CVE-2008-3431
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Aug 5, 2008
Updated: Dec 19, 2024
Summary
CVE-2008-3431 is a vulnerability affecting the VBoxDrvNtDeviceControl function in Sun xVM VirtualBox versions prior to 1.6.4. This issue stems from the use of the METHOD_NEITHER communication method for IOCTLs and insufficient validation of a buffer linked to the Irp object. Local users can exploit this weakness by opening the \\\\.\\VBoxDrv device and utilizing DeviceIoControl to transmit specially crafted kernel addresses, thereby gaining elevated privileges.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Oracle VM Virtualbox