目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2023-21987 PoC — Oracle Virtualization 安全漏洞

来源
关联漏洞
标题: Oracle Virtualization 安全漏洞 (CVE-2023-21987)
Description:Oracle Virtualization是美国甲骨文(Oracle)公司的一套虚拟化解决方案。该产品用于统一管理从应用程序到磁盘的整个硬件和软件体系,可实现从桌面到数据中心的虚拟化。 Oracle Virtualization 6.1.44 版本及之前版本和 7.0.8 版本及之前版本的 Core 组件存在安全漏洞。低权限攻击者利用该漏洞可以登录到 Oracle VM VirtualBox 执行的基础设施来破坏 Oracle VM VirtualBox。
Description
Oracle VirtualBox VGA OOB-Read Vulnerability
介绍
# cve-2023-21987-poc

## Oracle VirtualBox VGA OOB-Read Vulnerability

This Proof of Concept (PoC) is designed for a Linux guest OS running on a Windows host OS.

The purpose of this PoC is to demonstrate the ability to leak addresses of VirtualBox components. You may need to adjust the pointer values within the `vga_exp` function to match the specific builds you are testing.

Currently, the success rate is relatively low. Contributions to improve its reliability are highly appreciated.
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →