Impact
The vulnerability in Oracle VM VirtualBox 7.2.8 permits an attacker who already holds a local high-privileged account to compromise the virtual machine manager. Successful exploitation requires a second person to interact with the system, but once the conditions are met the attacker can create, delete, or modify critical data and can cause repeated crashes that result in a complete denial of service. Confidentiality is not directly impacted, however integrity and availability are significantly affected. The weakness can be classified as CWE-284 (Improper Access Control).
Affected Systems
Oracle Corporation’s Oracle VM VirtualBox version 7.2.8 is the only documented affected product. The CPE string confirms this version, and no other revisions are listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 7.4 indicates a high impact on integrity and availability, while the EPSS score of less than 1% suggests a very low probability of exploitation at present. The vulnerability is not listed in CISA KEV, meaning no publicly known active exploitation. Attackers would need local access and elevated privileges, and the need for user interaction from a different individual may further limit potential risk, though the scope-change attribute indicates that other Oracle products could be impacted once the exploit is successful.
OpenCVE Enrichment