Impact
A flaw in the Core component of Oracle VM VirtualBox permits a local logged‑in user to compromise the VirtualBox process with low privileges. The vulnerable 7.2.12 version can be abused to create, delete, or modify critical data that VirtualBox manages and can lead to a partial denial of service. The weakness is an improper access control problem that undermines the integrity and availability of VirtualBox data, as reflected in the CVSS vector showing high impact on integrity and low impact on availability.
Affected Systems
The affected product is Oracle VirtualBox version 7.2.12 from Oracle Corporation. No other versions or products are listed as impacted in the available CNA data.
Risk and Exploitability
The CVSS Base Score of 5.6 classifies the issue as moderate severity, and the EPSS figure of less than 1 % indicates that the probability of exploitation is currently very low. The vulnerability is not included in the CISA KEV catalog, suggesting it has not yet been widely exploited. Exploitation requires a local attacker with access to the infrastructure where VirtualBox runs and necessitates human interaction from a user other than the attacker, implying that social engineering or an internal collaborator would be needed for successful attacks.
OpenCVE Enrichment