Impact
The flaw exists in Oracle VM VirtualBox’s Core component and allows an attacker with high privileges who has logged into the host to compromise VirtualBox. Successful exploitation can grant the attacker control over VirtualBox, effectively leading to a takeover of the host, affecting confidentiality, integrity, and availability.
Affected Systems
Oracle VM VirtualBox versions 7.1.14 and 7.2.4 from Oracle Corporation are affected. The Core component in these releases contains the vulnerability.
Risk and Exploitability
The CVSS v3.1 score of 8.2 classifies the issue as high severity. The attack vector is local with high privilege; an attacker already needs local access to the host. The EPSS probability is below 1 %, indicating that widescale exploitation has not been observed, yet the potential for full host compromise drives a high impact rating. The vulnerability is not yet listed in the KEV catalog, but the severity and the control it grants warrant prompt action.
OpenCVE Enrichment