CVE-2024-21111 is an easily exploitable local vulnerability in the Core component of Oracle VM VirtualBox affecting supported versions prior to 7.0.16 on Windows hosts. A low-privileged attacker with logon access to the host system where VirtualBox is installed can exploit the flaw to compromise the VirtualBox installation and achieve takeover of the product. Available context associates this issue with Windows symbolic link abuse and local privilege escalation patterns, indicating the vulnerability is consistent with improper handling of link redirection during privileged file operations on attacker-controlled paths. The issue is local-only and does not apply to non-Windows hosts.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a local privilege escalation exploit for Oracle VirtualBox prior to version 7.0.16 (CVE-2024-21111) on Windows. The exploit leverages a flaw in VirtualBox's log rotation mechanism, where log files in C:\ProgramData\VirtualBox are moved or deleted as SYSTEM. By creating junctions and symbolic links, the attacker can trick VirtualBox into deleting or moving arbitrary files as SYSTEM, leading to privilege escalation. The repository is organized into two main exploit variants: one for arbitrary file deletion (VirtualBoxLPE_del) and one for arbitrary file move (VirtualBoxLPE_move). Each variant includes C++ source and header files implementing the exploit logic, as well as Visual Studio project files. The exploit requires local access and the ability to manipulate files in the VirtualBox data directory. No network endpoints are involved; all actions are performed locally on the file system. The code demonstrates advanced use of Windows file system features such as opportunistic locks, reparse points, and device symlinks to achieve its goal.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.