Impact
The vulnerability in the Shared Folders component of Oracle VM VirtualBox allows an attacker who has local logon to the host system to create, delete, or modify sensitive data stored in the shared folders. The flaw can be triggered using low‑privileged credentials, and the resulting impact is high confidentiality and integrity loss, as the modification or removal of critical data is possible. The CVE indicates no impact on availability, but the ability to tamper with data can compromise the integrity of virtual machines and their contents.
Affected Systems
This issue affects Oracle Corporation’s Oracle VM VirtualBox version 7.2.8. Only this specific version was listed in the advisory; other versions are not known to be vulnerable. The vulnerability resides in the virtual machine software responsible for handling shared folders between the host and guest operating systems.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate to high severity with a local attack vector, high attack complexity, low privileges required, and no need for user interaction. The EPSS score of less than 1% suggests that exploitation is unlikely in the wild, and the vulnerability is not catalogued in the CISA KEV list. However, because the defect allows an attacker with host access to compromise data on the virtual machine, the risk remains significant in environments where shared folders are enabled and local users have low privilege levels.
OpenCVE Enrichment