Sploitus

CVE-2008-3431

7 known exploits for CVE-2008-3431

The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to gain privileges by opening the \\.\VBoxDrv device and calling DeviceIoControl to send a crafted kernel address.

Affected products
Alt Linux, Virtualbox
Oracle Virtualbox
< 1.6.4
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
6.9% (94th percentile)
NVD status
Analyzed
Published
2008-08-05
CVE-2008-3431 at NVD
Authoritative description, scoring and affected products

7 known exploits for CVE-2008-3431

Proof-of-concept code and exploit modules indexed by Sploitus