Oracle VirtualBox Local Privilege Escalation CVE-2024-21111 Exploit

Oracle VirtualBox Local Privilege Escalation CVE-2024-21111 Exploit

vC++ by Prapattimynk

Oracle VirtualBox Prior to 7.0.16 is vulnerable to Local Privilege Escalation via Symbolic Link Following leading to Arbitrary File Delete and Arbitrary File Move.VirtualBox attempts to move log files

Android Android 5.0Exploits And POCs
( 523 ratings )
Price: $0
File Oracle VirtualBox Local Privilege Escalation CVE-2024-21111 Exploit
Publisher Prapattimynk
Genre Exploits And POCs
Size -
File Type C++
Os All
Mod Version C++
Report Report
Oracle VirtualBox Local Privilege Escalation CVE-2024-21111 Exploit is the most famous version in the Oracle VirtualBox Local Privilege Escalation CVE-2024-21111 Exploit series of publisher
Download

Oracle VirtualBox Prior to 7.0.16 is vulnerable to Local Privilege Escalation via Symbolic Link Following leading to Arbitrary File Delete and Arbitrary File Move.

VirtualBox attempts to move log files as NT AUTHORITY\SYSTEM in C:\ProgramData\VirtualBox (which all users can write to) to backup themselves by an ordinal, but MAX 10 logs. VirtualBox will also try to delete the 11th log as NT AUTHORITY\SYSTEM exposing itself to 2 bugs that lead to privilege escalation. Finding this bug was very interesting 🙂

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability applies to Windows hosts only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).



Recommended for You

You may also like

Comments

Your email address will not be published. Required fields are marked *

Next Post X
Ads Blocker Image Powered by Code Help Pro

AdBlocker Detected!!!

We have detected that you are using extensions to block ads. Please support us by disabling these ads blocker.