Impact
A flaw in the Core component of Oracle VM VirtualBox allows an attacker with local high privileges to take complete control of the VirtualBox instance, thereby compromising confidentiality, integrity, and availability of the virtualized environment; the defect also enables a scope change that could undermine additional Oracle virtualization products.
Affected Systems
Oracle Corporation’s Oracle VM VirtualBox product is affected, specifically versions 7.1.14 and 7.2.4, with the vulnerability present in both releases.
Risk and Exploitability
The vulnerability carries a CVSS 3.1 Base Score of 8.2 (AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H), signifying a severe local attack. The EPSS score of less than 1% indicates that exploitation in the wild is currently expected to be very rare. However, because the attack requires local high privileges, insiders or compromised host accounts could still leverage the flaw to fully compromise the VirtualBox instance. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment