|CVSS SCORE||8.2, (AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)|
The specific flaw exists within the VBoxVGA graphics controller component. When handling the VBoxVHWASurfaceBase object, the process does not properly validate the existence of the object prior to performing operations on the object. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the hypervisor.
Oracle has issued an update to correct this vulnerability. More details can be found at:
|CREDIT||Calvin Fong (Lord_Idiot) of STAR Labs