March 3, 2022 · Applied Cybernetics Group
CVE-2008-3431 — Oracle VirtualBox
Oracle VirtualBox Insufficient Input Validation Vulnerability
- Added to KEV
2022-03-03- Federal due date
2022-03-24- Vendor
- Oracle
- Product
- VirtualBox
- EPSS
- 90.3th percentile (score 0.054, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2008-3431
CISA short description
An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code.
Required action
Apply updates per vendor instructions.