Impact
The vulnerability is in the core component of Oracle VM VirtualBox 7.2.12 and is described as an authorization weakness that allows a local user with high privilege to bypass access controls. A successful exploitation grants the attacker read or write access to all VirtualBox‑managed data and the capability to cause a partial denial of service on the host. The weakness is mapped to privilege escalation (CWE‑269).
Affected Systems
Oracle VM VirtualBox version 7.2.12 installed on host machines within the infrastructure. No other product versions are listed as affected in the advisory.
Risk and Exploitability
The CVSS v3.1 base score of 6.1 reflects high confidentiality impact and low availability impact, with the attack vector classified as local and requiring high privileges. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not included in the CISA KEV catalog, suggesting no publicly known exploits. Based on the description, the likely attack vector is a local privilege exploitation in an environment where a trusted user has logged into the host system running VirtualBox.
OpenCVE Enrichment