A researcher has discovered a zero-day vulnerability in VirtualBox. While the discovery of zero-day bugs is no longer news, what makes this report interesting is that the researcher disclosed the flaw publicly without informing Oracle. So, a patch may not be released anytime soon.
Zero-Day Vulnerability in VirtualBox
Russian researcher Sergey Zelenyuk has reportedly discovered a security flaw in Oracle. The vulnerability could allow an attacker with root access to escape the virtual environment and gain access to the underlying operating system.
Note that the zero-day affects VirtualBox 5.2.20 and earlier versions.

Zelenyuk shared his findings with a detailed description on Github, explaining the technical details of the exploit. He reportedly tested the Intel PRO/1000 MT Desktop (82540EM), which he referred to as VirtualBox E1000 in his report.
"The E1000 has a vulnerability that allows an attacker with root privileges to escape to a ring3 host. The attacker can then use existing techniques to escalate privileges to ring 0 via /dev/vboxdrv."
The researcher emphasized that the vulnerability he found is “reliably exploitable.”
What does this mean?
This means it either always works or never, due to code complexity. It works at least on Ubuntu 16.04 and 18.04 x86_64 with default configuration.
As mentioned above, Zelenyuk did not inform Oracle about the vulnerability before the disclosure. He justified this action by citing his recent bad experience with Oracle. Specifically, last year, when a vulnerability was reported to Oracle, it took about 15 months to release the appropriate fix.
