Local Privilege Escalation in gksu under VirtualBox (CVE-2014-2943)

Earlier this week metasploit contributor Brandon Perry discovered a privilege escalation vulnerability in gksu running on the popular virtualization platform VirtualBox. It is important to note that Perry states the vulnerability is entirely the fault of gksu and that VBox does essentially what it is supposed to do. The linked article explains it all more thoroughly. It has now had CVE-2014-2943 assigned.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s