Exploitation Summary
EIP tracks 2 public exploits for CVE-2014-2477.
PoCs published by Metasploit, including Metasploit module exploits/windows/local/virtual_box_guest_additions.
AI-analyzed exploit summary This Metasploit module exploits a vulnerability in VirtualBox Guest Additions (VBoxGuest.sys) to achieve privilege escalation on Windows XP SP3 by corrupting the HalDispatchTable and executing arbitrary kernel code.
Description
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.26, 4.1.34, 4.2.26, and 4.3.12 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-2486.
Exploits (2)
This Metasploit module exploits a vulnerability in VirtualBox Guest Additions (VBoxGuest.sys) to achieve privilege escalation on Windows XP SP3 by corrupting the HalDispatchTable and executing arbitrary kernel code.
This Metasploit module exploits a memory corruption vulnerability in VirtualBox Guest Additions (VBoxGuest.sys) to achieve local privilege escalation on Windows XP SP3. It leverages arbitrary memory write to overwrite HalDispatchTable and execute shellcode via NtQueryIntervalProfile.