HomeSecurityZero-Day Vulnerability Discovered in Oracle's VirtualBox

Zero-Day Vulnerability Discovered in Oracle's VirtualBox

A researcher has discovered a zero-day vulnerability in VirtualBox. While the discovery of zero-day bugs is no longer news, what makes this report interesting is that the researcher disclosed the flaw publicly without informing Oracle. So, a patch may not be released anytime soon.

Zero-Day Vulnerability in VirtualBox

Russian researcher Sergey Zelenyuk has reportedly discovered a security flaw in Oracle. The vulnerability could allow an attacker with root access to escape the virtual environment and gain access to the underlying operating system.

Note that the zero-day affects VirtualBox 5.2.20 and earlier versions.

VirtualBox

Zelenyuk shared his findings with a detailed description on Github, explaining the technical details of the exploit. He reportedly tested the Intel PRO/1000 MT Desktop (82540EM), which he referred to as VirtualBox E1000 in his report.

"The E1000 has a vulnerability that allows an attacker with root privileges to escape to a ring3 host. The attacker can then use existing techniques to escalate privileges to ring 0 via /dev/vboxdrv."

The researcher emphasized that the vulnerability he found is “reliably exploitable.”

What does this mean?

This means it either always works or never, due to code complexity. It works at least on Ubuntu 16.04 and 18.04 x86_64 with default configuration.

As mentioned above, Zelenyuk did not inform Oracle about the vulnerability before the disclosure. He justified this action by citing his recent bad experience with Oracle. Specifically, last year, when a vulnerability was reported to Oracle, it took about 15 months to release the appropriate fix.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS