VirtualBox是由德国Innotek公司开发的开源虚拟化技术,目前已成为Sun xVM产品家族的成员。 Sun xVM VirtualBox1.6.4之前版本VBoxDrv.sys中的VBoxDrvNtDeviceControl存在本地权限提升漏洞。 由于该驱动未经任何验证便允许非特权用户以METHOD_NEITHER缓冲模式打开\\.\VBoxDrv设备,这就允许不可信任的用户态代码向驱动传送任意内核地址作为参数。通过特制的输入,恶意用户就可以使用内核中的功能执行任意内核态代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2008-3484 | eStoreAff index.php SQL注入漏洞 | |
| CVE-2008-3482 | Panasonic NetworkCamera 跨站脚本攻击漏洞 | |
| CVE-2008-3483 | ScrewTurn Software ScrewTurn Wiki 'System Log' Page HTML注入漏洞 | |
| CVE-2008-3356 | CA Ingres verifydb 本地权限提升漏洞 | |
| CVE-2008-3357 | CA Ingres ingvalidpw 权限许可和访问控制漏洞 | |
| CVE-2008-3389 | CA Ingres libbecompat 栈溢出漏洞 | |
| CVE-2008-3481 | CoppermineGallery CopperminePhotoGallery hemes/sample/theme.php 信息泄露漏洞 |
No comments yet