CVE-2008-3431
oracle virtualbox
Published 5 Aug 2008 · updated 16 Jun 2026 · Analyzed
8.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Mar 2022, with a remediation deadline of 24 Mar 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to gain privileges by opening the \\.\VBoxDrv device and calling DeviceIoControl to send a crafted kernel address.
References
- secunia.com/advisories/31361 · Broken Link, Vendor Advisory
- securityreason.com/securityalert/4107 · Broken Link
- securitytracker.com/id?1020625 · Broken Link, Third Party Advisory, VDB Entry
- sunsolve.sun.com/search/document.do?assetkey=1-66-240095-1 · Broken Link
- virtualbox.org/wiki/Changelog · Product
- www.coresecurity.com/content/virtualbox-privilege-escalation-vulnerability · Exploit, Third Party Advisory
- www.securityfocus.com/archive/1/495095/100/0/threaded · Broken Link, Third Party Advisory, VDB Entry
- www.securityfocus.com/bid/30481 · Broken Link, Exploit, Third Party Advisory
- www.vupen.com/english/advisories/2008/2293 · Broken Link
- exchange.xforce.ibmcloud.com/vulnerabilities/44202 · Third Party Advisory, VDB Entry
- www.exploit-db.com/exploits/6218 · Exploit, Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2008-3431 · US Government Resource