MorteNoir1 / virtualbox_e1000_0day

VirtualBox E1000 Guest-to-Host Escape
1.41k stars 199 forks source link

Oracle VM VirtualBox Extension Pack - clarification #2

Closed rjc closed 5 years ago

rjc commented 6 years ago

Hi @MorteNoir1,

In the text you didn't mention the Oracle VM VirtualBox Extension Pack. Is it a prerequisite? Does the exploit work both with and without it installed?

Thanks,

rjc

MorteNoir1 commented 6 years ago

Hi @rjc,

The extension pack isn't required. Guest additions in a guest aren't required as well. The exploit works on default configuration: you can create a VM, install an OS, and launch the exploit.

rjc commented 6 years ago

@MorteNoir1 Thanks for a prompt response!

The reason why I am inquiring is due to the Extension Pack adding Intel PXE boot ROM support and, since it's proprietary, I have no idea whether it changes anything else in terms of the virtual Intel NIC - hence my question, whether the exploit works with both - with and/or without the Extension Pack.

MorteNoir1 commented 5 years ago

@rjc The exploit works regardless of whether the Extension Pack is installed or not.

rjc commented 5 years ago

@MorteNoir1 Thanks for clarifying!