Impact
A local vulnerability exists in Oracle VM VirtualBox version 7.2.12 that allows an unauthenticated attacker with logon access to the host system to compromise the Core component. Based on the description, it is inferred that the weakness involves a race condition or improper permission handling, leading to integrity and availability impacts. Successful exploitation can cause repeated crashes of VirtualBox (complete denial of service) and provide unauthorized update, insert, or delete access to data managed by VirtualBox.
Affected Systems
The affected product is Oracle VM VirtualBox 7.2.12 from Oracle Corporation. No other versions or variants are listed as impacted.
Risk and Exploitability
The risk remains moderate, reflected by a CVSS score of 6.1. The EPSS score of < 1 % indicates a low predicted exploitation probability. Exploitation requires the attacker to be logged into the host and leverages a separate local user to provide the necessary interaction, limiting the attack surface to local environments. The vulnerability is not listed in the CISA KEV catalog, further reducing the likelihood of widespread exploitation at present.
OpenCVE Enrichment