Impact
A flaw in the Core component of Oracle VM VirtualBox 7.2.12 permits a low‑privileged attacker who has logged onto the host to gain full control over the VirtualBox environment, compromising the confidentiality, integrity and availability of the VirtualBox installation. The vulnerability is easily exploitable, requiring only local access, low complexity and no user interaction, and is classified as a privilege escalation failure (CWE‑269).
Affected Systems
The affected product is Oracle Corporation’s Oracle VM VirtualBox, specifically version 7.2.12. Hosts running this exact release may be compromised by a local attacker.
Risk and Exploitability
The CVSS 3.1 base score of 7.8 signals high severity for local attackers, while the EPSS score of less than 1% indicates a low exploitation probability in the wild. The vulnerability is not listed in the CISA KEV catalog, reducing its likelihood of being actively exploited. Nonetheless, the defect’s ease of exploitation and its impact on VirtualBox warrant prompt attention.
OpenCVE Enrichment