Impact
The vulnerability in Oracle VM VirtualBox version 7.2.12 allows a low‑privileged host user to execute a flaw that grants complete control over the VirtualBox application, effectively compromising the virtualization environment. This takeover results in loss of confidentiality, integrity, and availability for the virtualization host.
Affected Systems
Oracle Corporation's Oracle VM VirtualBox 7.2.12 is the vulnerable product. No other versions or platform variations are listed as affected.
Risk and Exploitability
The CVSS 3.1 base score of 7.8 indicates high severity with confidentiality, integrity, and availability impacts. The attack vector is local, requiring low authentication and no user interaction. The EPSS score is less than 1 %, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Despite the low exploit likelihood, the ability to take over VirtualBox makes it a significant risk in environments that run this software.
OpenCVE Enrichment