Impact
The flaw in Oracle VM VirtualBox 7.2.12 allows an attacker who already possesses high‑privilege access to the host machine to perform unauthorized updates, insertions, or deletions of data that the hypervisor can access. This activity results in a violation of data integrity, and because the vulnerability can cause a scope change, adjacent VirtualBox‑controlled components may also be affected.
Affected Systems
The affected product is Oracle VirtualBox version 7.2.12. No other versions or Oracle products are listed as impacted by this issue.
Risk and Exploitability
The CVSS score of 3.2 indicates a moderate integrity risk, and the EPSS score of less than 1% suggests that exploitation is unlikely but not impossible in environments where an attacker can log in locally with elevated privileges. The vulnerability is not listed in CISA KEV. Exploitation requires local presence and high privileges; the attacker can then modify VirtualBox data, potentially influencing the configuration or state of other components controlled by VirtualBox after a scope change.
OpenCVE Enrichment