CVE-2023-21987

HIGH

Oracle VM VirtualBox <6.1.44-7.0.8 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2023-21987. PoCs published by chunzhennn, minq0x1412.

AI-analyzed exploit summary This PoC demonstrates an out-of-bounds (OOB) read vulnerability in Oracle VirtualBox's VGA implementation (CVE-2023-21987), allowing address leakage of VirtualBox components. It uses DMA and VGA register manipulation to exploit the flaw, with a low success rate noted.

Description

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

Exploits (2)

nomisec WORKING POC 1 stars
by chunzhennn · poc
https://github.com/chunzhennn/cve-2023-21987-poc

This PoC demonstrates an out-of-bounds (OOB) read vulnerability in Oracle VirtualBox's VGA implementation (CVE-2023-21987), allowing address leakage of VirtualBox components. It uses DMA and VGA register manipulation to exploit the flaw, with a low success rate noted.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Complex
Reliability
Racy
Target: Oracle VirtualBox (specific version not specified)
No auth needed
Prerequisites: Linux guest OS on a Windows host OS · VirtualBox with vulnerable VGA implementation
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by minq0x1412 · poc
https://github.com/minq0x1412/CVE-2023-21987-and-CVE-2023-21991

This repository contains a functional Linux kernel module exploit for CVE-2023-21987, targeting VirtualBox's VMSVGA emulation. The exploit leverages out-of-bounds (OOB) read/write primitives via VGA and TPM MMIO to achieve arbitrary code execution in the host context.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Oracle VirtualBox (VMSVGA emulation)
No auth needed
Prerequisites: Linux guest VM with VirtualBox Guest Additions · VMSVGA graphics controller enabled · Kernel module loading privileges
devstral-2 · analyzed Jun 18, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0067
EPSS Percentile 47.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
oracle/vm_virtualbox < 6.1.44
Published Apr 18, 2023
Tracked Since Feb 18, 2026