CVE-2008-3431
05.08.2008, 19:41
The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to gain privileges by opening the \\.\VBoxDrv device and calling DeviceIoControl to send a crafted kernel address.Enginsight
| Vendor | Product | Version |
|---|---|---|
| oracle | virtualbox | 𝑥 < 1.6.4 |
𝑥
= Vulnerable software versions
Ubuntu Releases
References