CVE-2008-3431
KEVlargeLocal Code Execution via Input Validation Flaw in Sun xVM VirtualBox Driver
CISA: Oracle VirtualBox Insufficient Input Validation Vulnerability
An input validation vulnerability in VBoxDrv.sys, the Windows kernel driver used by Sun xVM VirtualBox, allows a local attacker to execute arbitrary code by sending crafted input through the driver. Because the flaw sits in a kernel driver, successful exploitation is likely to run attacker code with elevated privileges on the host. Any Windows host running an affected Sun xVM VirtualBox release is exposed, with the greatest risk on shared or multi-user machines where untrusted local users can run code. CISA added this flaw to the Known Exploited Vulnerabilities catalog on 2022-03-03, indicating known exploitation in the wild (ransomware use unknown); no public proof-of-concept is catalogued, and EPSS estimates a roughly 6.9% chance of exploitation within 30 days.
What to do: Apply updates per vendor instructions by upgrading to a current supported VirtualBox release, which replaces the vulnerable legacy VBoxDrv.sys driver. Because exploitation requires local access, restrict interactive logons on Windows hosts running VirtualBox and audit those hosts for the old driver. Organizations tracking CISA KEV (added 2022-03-03) should prioritize patching per the required action.
| Oracle (Sun Microsystems) Sun xVM VirtualBox (VBoxDrv.sys Windows kernel driver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code.
- Affected
- Oracle VirtualBox
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Oracle
- Products
- VirtualBox
- Weakness
- CWE-264