ZDI-26-639: Oracle VirtualBox VMSVGA Heap-based Buffer Overflow Local Privilege Escalation Vulnerability
ZDI disclosed a heap-based buffer overflow in Oracle VirtualBox's VMSVGA component (CVE-2026-71116) enabling local privilege escalation.
Zero Day Initiative published ZDI-26-639, a CVSS 7.5 heap-based buffer overflow in the VMSVGA component of Oracle VirtualBox. Local attackers who already execute high-privileged code on the guest system can leverage the flaw to escalate privileges on affected installations. The vulnerability is tracked as CVE-2026-71116. No exploitation is reported.
- Heap-based buffer overflow in VirtualBox VMSVGA, tracked as CVE-2026-71116
- CVSS 7.5 local privilege escalation on affected installations
- Requires prior high-privileged code execution on the guest system
- Disclosed as ZDI-26-639; no exploitation reported
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-71116 | Heap-Based Buffer Overflow in Oracle VM VirtualBox VMSVGA Enables Local Privilege Escalation CVE-2026-71116 is a vulnerability in the Core component of Oracle VM VirtualBox, which ZDI describes as a heap-based buffer overflow in the VMSVGA virtual graphics component that can be leveraged for local privilege escalation. It is difficult to exploit and requires a highly privileged attacker with logon to the infrastructure where VirtualBox executes, with no user interaction required. Successful attacks result in takeover of Oracle VM VirtualBox, and because the vulnerability has scope change, impact may extend to additional products beyond VirtualBox itself. Users running Oracle VM VirtualBox 7.2.14 are affected. There is currently no evidence of exploitation: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.1% probability of exploitation in the next 30 days. Do: Upgrade Oracle VM VirtualBox to the patched release provided in Oracle's Critical Patch Update for this CVE (the specific fixed version is not stated in the available data; verify via Oracle's advisory). Check installed versions with the VirtualBox About dialog or 'VBoxManage --version' and restrict high-privileged local accounts on systems running VirtualBox until patched. Given the low exploitation likelihood, no emergency action is required beyond routine patching. | 7.5 | <1% |
| massmillions of installations (VirtualBox has tens of millions of downloads; the share running the affected 7.2.14 release is unknown) |
This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-71116.
This source does not provide full text. Read it at zerodayinitiative.com.