CVE-2008-3431highunder attack

CVE-2008-3431

Published · Updated

71Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.8epss 6.9%
from disclosure to weapon
Published on NVDAug 5
CISA KEV+4958d
exploitation probability
6.9%top 6% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2022-03-24

Apply updates per vendor instructions.

In short

A flaw in VirtualBox's driver allows local users to gain elevated privileges by sending specially crafted commands to the VirtualBox device driver. The driver fails to properly check memory addresses before processing them, letting attackers execute code with system-level access.

Technical detail

CVE-2008-3431 exploits improper buffer validation in VBoxDrv.sys's VBoxDrvNtDeviceControl function, which uses METHOD_NEITHER for IOCTL handling without adequate address space verification. Local attackers with device access can trigger privilege escalation by sending crafted kernel pointers via DeviceIoControl calls, leading to arbitrary code execution in kernel context.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to gain privileges by opening the \\.\VBoxDrv device and calling DeviceIoControl to send a crafted kernel address.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.