Thinking Outside The Box [dusted off draft from 2017]

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A detailed technical analysis of CVE-2017-3558, a VM escape vulnerability in VirtualBox's Slirp-based NAT networking implementation. The bug stems from overwriting a trusted buffer length with an untrusted IP packet length field, bypassing all subsequent safety checks. The post demonstrates how to exploit this through heap

12m read timeFrom projectzero.google
Post cover image
Table of contents
PrefaceIntroductionThe packet heap in VirtualBoxThe VulnerabilityExploitation: Going up to host userspaceConclusion [from the future]

Sort: