CVE-2025-53024 is an easily exploitable vulnerability in the Core component of Oracle VM VirtualBox 7.1.10. A high-privileged attacker with logon access to the infrastructure hosting VirtualBox can compromise the VirtualBox installation. The vulnerability may also affect additional products beyond VirtualBox.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact native C exploit project for CVE-2025-53024. It contains a Makefile, a minimal README, one main exploit source file (exp.c), helper code for interacting with the VMware SVGA virtual graphics device (svga.c / svga.h), and bundled VMware SVGA register/type headers (svga_reg.h, svga_types.h). The exploit is not network-based; it is a local, hardware/virtual-device-facing exploit that directly accesses PCI configuration space and VMware SVGA framebuffer/FIFO memory from a privileged Linux context. The helper code enumerates the VMware SVGA II PCI device using libpciaccess, requires root privileges, enables I/O privilege level 3 via iopl(3), maps framebuffer and FIFO BARs, and exposes primitives to read/write SVGA registers and submit FIFO commands. The main exploit logic in exp.c uses crafted SVGA FIFO commands (notably SVGA_CMD_DEFINE_SCREEN and SVGA_CMD_RECT_COPY) to perform an out-of-bounds copy from VRAM offset 0x006b3044 to 0x010501b8, overwriting what the author labels as a PCI entry structure. The overwritten structure contains attacker-controlled values for pvUser, pDevIns, and a callback/function pointer. After corruption, a write to PCI config data port 0xCFC triggers the hijacked callback. The exploit first uses this primitive for memory disclosure: it points the callback to a read-like function inside VBoxDD, leaks an imported function pointer (GetVersionExA IAT entry), reconstructs the kernel32 base, and derives the WinExec address using hardcoded offsets. It then repeats the corruption with the callback set to WinExec and places the ASCII string "calc" in controlled memory, causing the target to execute calc as a proof-of-concept payload. Notable characteristics: - Highly version-specific hardcoded offsets: OOB_SRC_OFF, PCI_ENTRY_OFF, VBoxDD base delta, read function offset, IAT offset, and WinExec offset. - Requires a very specific virtualization/device layout and likely a matching vulnerable build. - Demonstrates both arbitrary read and code execution, not just crash or detection. - No C2, network beacons, or external URLs/domains are present. Repository structure and purpose: - exp.c: primary exploit chain and payload logic. - svga.c / svga.h: PCI/SVGA initialization, FIFO submission, register access, and VRAM helpers. - svga_reg.h / svga_types.h: vendor header definitions for VMware SVGA registers, commands, and types. - Makefile: builds the exploit as ./exp linked against libpciaccess. - README.md: only identifies the CVE. Overall, this is a real proof-of-concept exploit repository demonstrating local exploitation through a virtual graphics device interface to achieve controlled callback hijacking and command execution.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.