Impact
Vulnerability exists in the Core component of Oracle VM VirtualBox 7.2.6. A high‑privileged attacker who has logged on to the host system can exploit local privilege escalation to compromise the VirtualBox process, giving the attacker full control of the virtualization environment. The flaw can lead to significant confidentiality, integrity and availability impacts, and the description notes that attacks may also affect other products due to a scope change.
Affected Systems
Oracle Corporation’s Oracle VM VirtualBox 7.2.6 is the only version explicitly identified as affected.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates a high level of severity. With no EPSS score provided, the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local; the attacker must have privileged access to the host machine. If successfully exploited, the attacker can take over VirtualBox, potentially pivoting to other services or systems that rely on converged virtualization. Given the scope change, the risk extends beyond the VirtualBox instance itself.
OpenCVE Enrichment