Impact
The flaw resides in the VMSVGA device of Oracle VM VirtualBox, version 7.2.8. A locally authenticated attacker who can log on to the host system may exploit it to raise privileges within the virtual machine environment. Successful exploitation would allow total compromise of the virtual machine, resulting in loss of confidentiality, integrity, and availability for that VM as well as any additional products affected by scope changes. The weakness is rooted in improper privilege management.
Affected Systems
Oracle Corporation’s Oracle VM VirtualBox 7.2.8 is explicitly impacted. The advisory notes that attacks on this product may also threaten other Oracle products due to a scope change, although no other specific products are listed.
Risk and Exploitability
The CVSS base score of 7.5 denotes high severity, and the EPSS score of less than 1 % indicates the vulnerability is presently considered unlikely to be exploited in the wild. The attack vector is local and requires an already authenticated session on the host; therefore the risk is concentrated in environments where privileged users can launch virtual machines. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed public exploitation at this time.
OpenCVE Enrichment