Impact
The vulnerability resides in the Core component of Oracle VM VirtualBox 7.2.12 and permits an attacker who is a high‑privileged user with local logon to the host machine to read a subset of data that should be restricted, representing an Information Exposure weakness (CWE‑200). The weakness results in a confidentiality impact, with no influence on integrity or availability. The CVSS vector indicates a local attack that requires high privileges and results in read‑only exposure, leading to a Base Score of 3.2.
Affected Systems
Oracle Corporation’s virtual machine platform, Oracle VM VirtualBox, specifically version 7.2.12 is affected. No other precise versions are listed, but the text suggests the issue may also influence other products within the Oracle Virtualization suite due to a scope change.
Risk and Exploitability
The CVSS score of 3.2 coupled with an EPSS score of less than 1% signifies a low overall exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local access to a machine running the affected VirtualBox instance and requires high‑privilege credentials, limiting the attacker’s reach to machine‑level controls.
OpenCVE Enrichment