Impact
A vulnerable component in the core of Oracle VM VirtualBox permits an attacker who has local access to the host to compromise the VirtualBox process, leading to a full takeover of the virtualization environment. The flaw causes loss of confidentiality, integrity, and availability of the VirtualBox service, essentially allowing the attacker to operate with the same privileges as VirtualBox itself.
Affected Systems
Oracle Corporation’s VirtualBox 7.2.12 for Windows hosts is affected; no other versions or operating systems are listed as vulnerable.
Risk and Exploitability
The vulnerability has a CVSS v3.1 base score of 7.8, indicating high severity, yet the EPSS score is below 1 % and it is not currently listed in CISA’s KEV catalog. The likely attack vector requires an attacker to have a local account or otherwise log on to the infrastructure where VirtualBox is running. Successful exploitation enables the attacker to take over the VirtualBox service, potentially leading to the compromise of virtual machines and other host functions.
OpenCVE Enrichment