Impact
A flaw in the Core component of Oracle VM VirtualBox 7.2.12 allows an attacker who has a high‑privileged logon to the host infrastructure to fully compromise the VirtualBox instance. The CVSS 3.1 score of 7.5 reflect significant effects on confidentiality, integrity and availability, and the exploit can lead to a complete takeover of the VirtualBox installation.
Affected Systems
Oracle Corporation’s Oracle VM VirtualBox product, specifically version 7.2.12, is affected. No other versions are listed as vulnerable.
Risk and Exploitability
An attacker must already have high privileged access on the host (AV:L, PR:H) and does not need a user interface (UI:N). The EPSS score is less than 1 %, indicating current exploitation probability is low, and the vulnerability is not included in the CISA KEV catalog. Based on the description, it is inferred that successful exploitation may impact additional products, indicating potential pivot to compromise other components within the same infrastructure. Nonetheless, the impact remains grave; if exploited, the attacker can achieve full control over the VirtualBox instance and potentially extend influence to other parts of the environment.
OpenCVE Enrichment