VirtualBox's emulated NICs, the Intel e1000 and the AMD PCNet, process the guest's transmit and receive descriptor rings and packet buffers in the host-side VM process. These adapters have a well-documented history of guest-to-host escapes, with crafted descriptors and packet data triggering memory corruption on the host.
Network-adapter escape surface:
- e1000: TX/RX descriptor rings, offload handling
- PCNet: descriptor and buffer handling
Exploitation notes#
- The e1000 is present by default on many guest types, making it broadly reachable.
- Public, complete guest-to-host exploit chains exist for these adapters, a good source of concrete technique.
- Code execution lands in the host VM process as the launching user, then escalates.