vendor:
VirtualBox
by:
Google Project Zero
8.8
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: VirtualBox
Affected Version From:
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: a:oracle:virtualbox
Platforms Tested: Linux
VirtualBox Privilege Escalation
This exploit allows an unprivileged userspace process to escalate into the VirtualBox process, compromising the host kernel. It takes advantage of the loading of arbitrary shared libraries via dlopen() in the libasound library, which is loaded by the privileged VM host process for VMs with ALSA audio.
Mitigation:
Update VirtualBox to the latest version, which includes a fix for this vulnerability.