7.2
CVE-2015-6923
- EPSS 0.92%
- Veröffentlicht 21.09.2015 19:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The ndvbs module in VBox Communications Satellite Express Protocol 2.3.17.3 allows local users to write to arbitrary physical memory locations and gain privileges via a 0x00000ffd ioctl call.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Vboxcomm ≫ Satellite Express Protocol Version2.3.17.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.92% | 0.557 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
http://packetstormsecurity.com/files/133620/VBox-Satellite-Express-Arbitrary-Write-Privilege-Escalation.html
http://seclists.org/fulldisclosure/2015/Sep/72
http://www.securityfocus.com/archive/1/536491/100/0/threaded
https://www.exploit-db.com/exploits/38225/
https://www.korelogic.com/Resources/Advisories/KL-001-2015-005.txt