Lucene search

K
zdiZiming zhang from Codesafe Team of Legendsec at Qi'anxin GroupZDI-20-901
HistoryJul 20, 2020 - 12:00 a.m.

Oracle VirtualBox virtio-net Out-Of-Bounds Read Information Disclosure Vulnerability

2020-07-2000:00:00
ziming zhang from Codesafe Team of Legendsec at Qi'anxin Group
www.zerodayinitiative.com
25
oracle virtualbox
virtio-net
out-of-bounds read
information disclosure
vulnerability
high-privileged code
transmission component
user-supplied data
allocated buffer
escalate privileges
hypervisor.

EPSS

0.001

Percentile

28.7%

This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the virtio-net transmission component. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute code in the context of the hypervisor.