Post from 2024-02-22 07:12:26

[Alex Plaskett @ X] RT by @alexjplaskett: Last year I discovered multiple bugs in virtio-net for VirtualBox (CVE-2023-22098, CVE-2023-22099, CVE-2023-22100) and wrote a 100% reliable VM escape using an out-of-bounds write (with ASLR defeat). Published the exploit code:

https://github.com/google/security-research/tree/master/pocs/oracle/virtualbox/cve-2023-22098
permalink | main