ZeroHour
Product

Oracle VirtualBox

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

ZDI-26-640: Oracle VirtualBox VirtioSCSI Uninitialized Memory Information Disclosure Vulnerability

ZDI detailed an uninitialized memory flaw in Oracle VirtualBox's VirtioSCSI (CVE-2026-71132) allowing local attackers to disclose sensitive information.

Zero Day Initiative published ZDI-26-640, a CVSS 5.3 information disclosure vulnerability in the VirtioSCSI component of Oracle VirtualBox. An attacker must first run high-privileged code on the guest system before the uninitialized memory issue can be used to disclose sensitive information. The flaw is tracked as CVE-2026-71132. The advisory reports no exploitation activity.

ZDI-26-639: Oracle VirtualBox VMSVGA Heap-based Buffer Overflow Local Privilege Escalation Vulnerability

ZDI disclosed a heap-based buffer overflow in Oracle VirtualBox's VMSVGA component (CVE-2026-71116) enabling local privilege escalation.

Zero Day Initiative published ZDI-26-639, a CVSS 7.5 heap-based buffer overflow in the VMSVGA component of Oracle VirtualBox. Local attackers who already execute high-privileged code on the guest system can leverage the flaw to escalate privileges on affected installations. The vulnerability is tracked as CVE-2026-71116. No exploitation is reported.

Related CVEs

  • Heap-Based Buffer Overflow in Oracle VM VirtualBox VMSVGA Enables Local Privilege Escalation
    CVE-2026-71116 is a vulnerability in the Core component of Oracle VM VirtualBox, which ZDI describes as a heap-based buffer overflow in the VMSVGA virtual graphics component that can be leveraged for local privilege escalation. It is difficult to exploit and requires a highly privileged attacker with logon to the infrastructure where VirtualBox executes, with no user interaction required. Successful attacks result in takeover of Oracle VM VirtualBox, and because the vulnerability has scope change, impact may extend to additional products beyond VirtualBox itself. Users running Oracle VM VirtualBox 7.2.14 are affected. There is currently no evidence of exploitation: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.1% probability of exploitation in the next 30 days.
    · Oracle VM VirtualBox (Core) 7.2.14 (the supported version listed as affected by Oracle)mass
  • Information Disclosure in Oracle VM VirtualBox 7.2.14 (VirtioSCSI)
    CVE-2026-71132 is a flaw in the core of Oracle VM VirtualBox, tagged CWE-284 (improper access control); the related ZDI advisory (ZDI-26-640) describes it as an uninitialized-memory information disclosure in VirtualBox's VirtioSCSI handling. It is difficult to exploit (high attack complexity) and requires a high-privileged attacker with local logon to the infrastructure where VirtualBox runs, with no user interaction needed. A successful attack yields unauthorized access to critical data or complete access to all VirtualBox-accessible data, and because of a scope change the impact can extend to additional products beyond VirtualBox itself; there is no integrity or availability impact. Per Oracle's advisory, the supported version affected is VirtualBox 7.2.14, so hosts running that release are exposed. No exploitation is currently known: it is not in CISA's KEV, no public proof-of-concept exists, and EPSS estimates only a 0.1% probability of exploitation in the next 30 days.
    · Oracle VM VirtualBox 7.2.14 (affected supported version per the advisory; no other version ranges specified in the data)mass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.