Impact
A vulnerability in Oracle VM VirtualBox 7.2.12 stems from an Access Control weakness (CWE‑284). It permits a low‑privileged user with local logon access to create, delete, or modify data within the VirtualBox environment, and to induce a partial denial of service. The impact is a high‑risk integrity breach for VirtualBox‑managed data and a medium‑risk availability disruption.
Affected Systems
Oracle VirtualBox 7.2.12 on any host system is affected. The flaw may also influence other products that are used in conjunction with VirtualBox because the vulnerability’s scope is marked as "change," indicating that exploitation can affect additional components.
Risk and Exploitability
The CVSS 3.1 base score of 6.4 indicates moderate severity with high integrity impact and low availability impact. The EPSS score is less than 1%, showing a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation requires local access from a user with low privileges on the host system, making it less attractive to threat actors but still relevant for in‑house adversaries or compromised accounts. The high difficulty of exploitation (AC:H, PR:L) limits the likelihood of successful attacks, though the potential damage remains significant.
OpenCVE Enrichment