ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 6 sources: “Zero Day Initiative publishes six Oracle VirtualBox advisories (ZDI-26-639 through ZDI-26-644) covering VMSVGA, VirtioSCSI, and IDisplay local guest flaws” — merged summary and timeline →

ZDI-26-644: Oracle VirtualBox VMSVGA Race Condition Local Privilege Escalation Vulnerability

mediumAdvisoryimportance 26CVE-2026-60155
AI summary · glm-5.3-flash

ZDI publishes ZDI-26-644 for CVE-2026-60155, a race condition local privilege escalation in Oracle VirtualBox VMSVGA, rated CVSS 7.5.

Zero Day Initiative published advisory ZDI-26-644 describing a race condition in Oracle VirtualBox's VMSVGA component. Local attackers who already execute high-privileged code on the guest system can escalate privileges on affected installations. ZDI rated the issue CVSS 7.5 and assigned CVE-2026-60155.

  • Race condition in VMSVGA enables guest privilege escalation
  • Requires pre-existing high-privileged code execution on the guest
  • CVSS 7.5; tracked as CVE-2026-60155
VendorsOracle
ProductsVirtualBox
OrganizationsZero Day Initiative

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-60155
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component:

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

NVD description · AI analysis pending
7.5<1%
  • oracle vm virtualbox
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-60155.

This source does not provide full text. Read it at zerodayinitiative.com.