Impact
The vulnerability exists in the core component of Oracle VM VirtualBox version 7.2.6 and allows a user who is already logged in with high privileges to compromise the VirtualBox instance. The flaw affects confidentiality, integrity, and availability of the virtual environment and, due to the scope-change flag, could also impact other products that rely on VirtualBox. The CVSS base score is 7.5 with a local attacker (AV:L) and high privilege (PR:H), with no user interaction required.
Affected Systems
Oracle Corporation’s Oracle VM VirtualBox version 7.2.6, as identified by the CPE cpe:2.3:a:oracle:vm_virtualbox:7.2.6:*:*:*:*:*:*:*
Risk and Exploitability
The CVSS score indicates high severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, suggesting that no active exploitation has been documented. The local attack vector requires the attacker to have high‑privilege access on the host, meaning an insider or compromised account could exploit the weakness. Because the scope changes to other products, this risk could propagate beyond the VM itself, but the exploitation does not involve external network reachability.
OpenCVE Enrichment