CVE
- Id
- 33548
- CVE No.
- CVE-2008-3431
- Status
- Candidate
- Description
- The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to gain privileges by opening the \.VBoxDrv device and calling DeviceIoControl to send a crafted kernel address.
- Phase
- Assigned (20080731)
- Votes
- None (candidate not yet proposed)
- Comments