Sun xVM VirtualBox Local Privilege Escalation Vulnerability
BID:34080
Info
Sun xVM VirtualBox Local Privilege Escalation Vulnerability
| Bugtraq ID: | 34080 |
| Class: | Design Error |
| CVE: |
CVE-2009-0876 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 10 2009 12:00AM |
| Updated: | May 11 2009 05:46PM |
| Credit: | Sun |
| Vulnerable: |
Sun xVM VirtualBox 2.0 Sun xVM VirtualBox 2.1 Pardus Linux 2008 0 |
| Not Vulnerable: |
Sun xVM VirtualBox 2.1.4r43001 Sun xVM VirtualBox 2.0.6r43001 |
Discussion
Sun xVM VirtualBox Local Privilege Escalation Vulnerability
Sun xVM VirtualBox is prone to a local privilege-escalation vulnerability.
An attacker can exploit this vulnerability to run arbitrary code with superuser privileges.
The following versions for the Linux platform are vulnerable:
Sun xVM VirtualBox 2.0
Sun xVM VirtualBox 2.1
Sun xVM VirtualBox is prone to a local privilege-escalation vulnerability.
An attacker can exploit this vulnerability to run arbitrary code with superuser privileges.
The following versions for the Linux platform are vulnerable:
Sun xVM VirtualBox 2.0
Sun xVM VirtualBox 2.1
Exploit / POC
Sun xVM VirtualBox Local Privilege Escalation Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following example exploit is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following example exploit is available:
Solution / Fix
Sun xVM VirtualBox Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Sun xVM VirtualBox Local Privilege Escalation Vulnerability
References:
References: