ZeroHour

CVE-2008-3431

KEVlarge

Local Code Execution via Input Validation Flaw in Sun xVM VirtualBox Driver

CISA: Oracle VirtualBox Insufficient Input Validation Vulnerability

CVSS
EPSS
7%p94
Published
KEV added
AI analysis

An input validation vulnerability in VBoxDrv.sys, the Windows kernel driver used by Sun xVM VirtualBox, allows a local attacker to execute arbitrary code by sending crafted input through the driver. Because the flaw sits in a kernel driver, successful exploitation is likely to run attacker code with elevated privileges on the host. Any Windows host running an affected Sun xVM VirtualBox release is exposed, with the greatest risk on shared or multi-user machines where untrusted local users can run code. CISA added this flaw to the Known Exploited Vulnerabilities catalog on 2022-03-03, indicating known exploitation in the wild (ransomware use unknown); no public proof-of-concept is catalogued, and EPSS estimates a roughly 6.9% chance of exploitation within 30 days.

What to do: Apply updates per vendor instructions by upgrading to a current supported VirtualBox release, which replaces the vulnerable legacy VBoxDrv.sys driver. Because exploitation requires local access, restrict interactive logons on Windows hosts running VirtualBox and audit those hosts for the old driver. Organizations tracking CISA KEV (added 2022-03-03) should prioritize patching per the required action.

Affected
Oracle (Sun Microsystems) Sun xVM VirtualBox (VBoxDrv.sys Windows kernel driver)
Estimated exposure
largeon the order of 100,000+ legacy Windows hosts (clearly an estimate) — VirtualBox is one of the most widely deployed desktop hypervisors with tens of millions of cumulative downloads, but this 2008-era driver flaw only affects hosts still running unpatched old releases, so a six-figure count of remaining…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code.

CISA Known Exploited Vulnerability
Affected
Oracle VirtualBox
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Oracle
Products
VirtualBox
Weakness
CWE-264

In the news