Hey, I played in that CTF! Although, I ended up spending most of my time pwning QEMU instead. There was an easier challenge, aptly named Easy Escape, in which the organizers added a vulnerable memory-mapped device to QEMU. The device had the ability to read and write certain memory, so the exploit ended up being an attack where you triggered a memory operation which accessed the device's own memory - essentially causing the device's MMIO handler to recurse. That in turn set up a use-after-free situation which could be exploited for the win.
I love Real World CTF. In 2018 I participated in the finals round held in Zhengzhou, and there was a problem that involved Java and the RMI protocol. We ended up exploiting two zero-days in Java, reported them to Oracle and got a CVE: CVE-2019-2684. That was very exciting to me - to discover and exploit a bug in real software in less than 48 hours :)
Kudos to the VirtualBox hackers for doing that on such a high-profile bit of software - amazing work!