CVE-2015-6923: Vboxcomm Satellite Express Protocol

High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.

The ndvbs module in VBox Communications Satellite Express Protocol 2.3.17.3 allows local users to write to arbitrary physical memory locations and gain privileges via a 0x00000ffd ioctl call.

Affected products

  • Vboxcomm Satellite Express Protocol: version 2.3.17.3 only

Published 2015-09-21. Last modified 2026-06-17.