Impact
The vulnerability resides in the core component of Oracle VM VirtualBox 7.2.12 and allows an attacker with high‑privileged local access on the host to take full control of the VirtualBox application. The flaw can compromise confidentiality, integrity, and availability of the virtualized environment. Based on the description, a takeover of the VirtualBox process could potentially affect the host system, but this is an inference.
Affected Systems
Oracle VM VirtualBox version 7.2.12, the only affected version listed. The product is Oracle Corporation’s virtualization platform.
Risk and Exploitability
The CVSS v3.1 Base Score of 7.5 reflects the high severity of this local privilege escalation. The EPSS score is reported as <1%, indicating that attacks are anticipated to be rare. The alert is not listed in CISA’s KEV catalog, but the scope change vector (S:C) in the CVSS definition signals that successful exploitation could affect other products that depend on VirtualBox components. Successful exploitation requires an attacker to first log on locally with high privileges and then trigger the exploit to gain control of both the VirtualBox process and any dependent components; while a takeover of the VirtualBox process could potentially influence the host, this impact is inferred from the description.
OpenCVE Enrichment