Impact
The Oracle VM VirtualBox 7.2.12 product contains a flaw in its Core component that permits an actor with high‑privilege local access to read data that is otherwise protected. The weakness maps to information‑disclosure (CWE‑200) and is limited to confidentiality; there is no privilege escalation or disruption of host or guest systems. The description states the desire for high‑privilege logon, so the likely attack vector is local and requires elevated rights, as inferred from the advisory wording.
Affected Systems
Only Oracle Corporation’s VirtualBox version 7.2.12 is explicitly listed as affected. The CPE confirms this version, and no other vendors or product variations are known. The advisory mentions that other products may be impacted, but no specific details are provided.
Risk and Exploitability
The overall risk is low, with a CVSS base score of 3.2 and an EPSS probability of less than 1%. It is not included in the CISA KEV catalog. Because the vulnerability relies on local high‑privileged logon, remote exploitation is not possible. A successful exploit would grant unauthorized read access to a subset of data handled by VirtualBox, with potential indirect impact if scope expands, but no integrity or availability damage is expected.
OpenCVE Enrichment