CVE-2012-3221

Oracle VM VirtualBox 3.2, 4.0, 4.1 - Denial of Service in VirtualBox Core

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-3221. PoCs published by halfdog.

AI-analyzed exploit summary This exploit triggers a local denial-of-service in Oracle VM VirtualBox by executing an interrupt (int $0x8) via inline assembly. The PoC is minimal and directly demonstrates the vulnerability without additional payloads.

Description

Unspecified vulnerability in the Oracle VM Virtual Box component in Oracle Virtualization 3.2, 4.0, and 4.1 allows local users to affect availability via unknown vectors related to VirtualBox Core. NOTE: The previous information was obtained from the October 2012 CPU. Oracle has not commented on claims from another vendor that this issue is related to "incorrect interrupt handling."

Exploits (1)

exploitdb WORKING POC
by halfdog · cdoslinux_x86-64
https://www.exploit-db.com/exploits/21224

This exploit triggers a local denial-of-service in Oracle VM VirtualBox by executing an interrupt (int $0x8) via inline assembly. The PoC is minimal and directly demonstrates the vulnerability without additional payloads.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Oracle VM VirtualBox (versions affected by CVE-2012-3221)
No auth needed
Prerequisites: Local access to the target system · Execution privileges to run the compiled binary
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/56045
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/79380
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1027666
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16681
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2012/dsa-2594
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150

Scores

EPSS 0.0079
EPSS Percentile 51.3%

Details

Status published
Products (3)
oracle/virtualization 3.2
oracle/virtualization 4.0
oracle/virtualization 4.1
Published Oct 17, 2012
Tracked Since Feb 18, 2026