logo

CVE-2024-21115: An Oracle VirtualBox LPE Used to Win Pwn2Own

ID: 44b36c2a-cae1-5dea-80c3-29ba30a71a9f

STIX ID: report--44b36c2a-cae1-5dea-80c3-29ba30a71a9f

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
45/100

Date Published: 2024-05-09

Date Updated: 2026-05-01

Author: Guest Blogger

...
...

This excerpt analyzes a VirtualBox synchronization vulnerability: by flipping a byte (0x23 -> 0x21) the author creates a race between threads holding the VMMDev and VGA critical sections to wake a VGA-waiting thread prematurely. The attempt is unstable — the racing thread changes NativeThreadOwner and causes a SigTrap when the original thread later unlocks the critical section — so the write-up documents an exploit-development effort rather than a confirmed, successful attack.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.