Impact
The vulnerability resides in the core component of Oracle VM VirtualBox 7.2.6 and permits an attacker with local host credentials to gain unauthorized access to the VirtualBox installation. This flaw can lead to confidentiality compromise of all data accessible through VirtualBox, including the contents of virtual machine images and host‑side configuration files. The defect represents an improper access control issue that allows privileged local users to subvert access restrictions imposed by VirtualBox.
Affected Systems
Affected systems include Oracle Corporation's Oracle VM VirtualBox version 7.2.6. No other product or version has been identified as impacted in the current advisory.
Risk and Exploitability
The CVSS v3.1 base score of 6.0 indicates a medium severity, with local access and low authentication complexity reducing the barrier for exploitation. The EPSS score is not available, but the vulnerability is not listed in the CISA KEV catalog. The described local attack vector requires an attacker to have logon to the host system and privileged credentials, and the impact is scoped to the VirtualBox environment, potentially affecting additional connected products due to the change in scope. Because the exploit relies on local privileges, the risk remains high for environments where the host is not properly secured or where critical data resides within virtual machines.
OpenCVE Enrichment