Oracle VM VirtualBox for Windows prior to 7.0.16 - Elevation of Privileges
A vulnerability has been identified in Oracle VM VirtualBox on Windows where the setup fails to set proper access rights for its installation folder if a non-default installation path was chosen during installation. This allows any authenticated local attacker to inject arbitrary code and escalate privileges to the SYSTEM context.
Oracle VM VirtualBox up to 7.0.14
fixed starting with 7.0.16
Service Name: VBoxSDS (non-default installation path)
- Alaa Kachouh
- Ali Jammal of Deloitte Netherlands