ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 6 sources: “Zero Day Initiative publishes six Oracle VirtualBox advisories (ZDI-26-639 through ZDI-26-644) covering VMSVGA, VirtioSCSI, and IDisplay local guest flaws” — merged summary and timeline →

ZDI-26-639: Oracle VirtualBox VMSVGA Heap-based Buffer Overflow Local Privilege Escalation Vulnerability

mediumVulnerabilityimportance 27CVE-2026-71116
AI summary · glm-5.3-flash

ZDI disclosed a heap-based buffer overflow in Oracle VirtualBox's VMSVGA component (CVE-2026-71116) enabling local privilege escalation.

Zero Day Initiative published ZDI-26-639, a CVSS 7.5 heap-based buffer overflow in the VMSVGA component of Oracle VirtualBox. Local attackers who already execute high-privileged code on the guest system can leverage the flaw to escalate privileges on affected installations. The vulnerability is tracked as CVE-2026-71116. No exploitation is reported.

  • Heap-based buffer overflow in VirtualBox VMSVGA, tracked as CVE-2026-71116
  • CVSS 7.5 local privilege escalation on affected installations
  • Requires prior high-privileged code execution on the guest system
  • Disclosed as ZDI-26-639; no exploitation reported

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-71116
Heap-Based Buffer Overflow in Oracle VM VirtualBox VMSVGA Enables Local Privilege Escalation

CVE-2026-71116 is a vulnerability in the Core component of Oracle VM VirtualBox, which ZDI describes as a heap-based buffer overflow in the VMSVGA virtual graphics component that can be leveraged for local privilege escalation. It is difficult to exploit and requires a highly privileged attacker with logon to the infrastructure where VirtualBox executes, with no user interaction required. Successful attacks result in takeover of Oracle VM VirtualBox, and because the vulnerability has scope change, impact may extend to additional products beyond VirtualBox itself. Users running Oracle VM VirtualBox 7.2.14 are affected. There is currently no evidence of exploitation: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.1% probability of exploitation in the next 30 days.

Do: Upgrade Oracle VM VirtualBox to the patched release provided in Oracle's Critical Patch Update for this CVE (the specific fixed version is not stated in the available data; verify via Oracle's advisory). Check installed versions with the VirtualBox About dialog or 'VBoxManage --version' and restrict high-privileged local accounts on systems running VirtualBox until patched. Given the low exploitation likelihood, no emergency action is required beyond routine patching.

7.5<1%
  • Oracle VM VirtualBox (Core) 7.2.14 (the supported version listed as affected by Oracle)
massmillions of installations (VirtualBox has tens of millions of downloads; the share running the affected 7.2.14 release is unknown)
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-71116.

This source does not provide full text. Read it at zerodayinitiative.com.