May 9, 2024, 6:15 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

In this guest blog from Master of Pwn winner Cody Gallagher, he details CVE-2024-21115 – an Out-of-Bounds (OOB) Write that occurs in Oracle VirtualBox that can be leveraged for privilege escalation. This bug was recently patched by Oracle in April. Cody has graciously provided this detailed write-up of the vulnerability and how he exploited it at the contest.


The core bug used for this escape is a relative bit clear on the heap from the VGA device. The bug is …

april blog bug can cve cve-2024 escalation guest blog lpe master oob oracle oracle virtualbox out-of-bounds privilege privilege escalation pwn2own virtualbox vulnerability winner write-up

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Senior Security Researcher - Linux MacOS EDR (Cortex)

@ Palo Alto Networks | Tel Aviv-Yafo, Israel

Sr. Manager, NetSec GTM Programs

@ Palo Alto Networks | Santa Clara, CA, United States

SOC Analyst I

@ Fortress Security Risk Management | Cleveland, OH, United States