Impact
An exploitable flaw in the core component of Oracle VM VirtualBox 7.2.14 allows a high‑privileged local user to gain unauthorized access to all VirtualBox data the service can read, potentially exposing sensitive configuration files, virtual machine images, or other critical assets. The impact manifests as confidentiality loss for data that the VirtualBox service can access, with no immediate impact on integrity or availability reported.
Affected Systems
The affected system is Oracle VirtualBox 7.2.14, provided by Oracle Corporation. The vulnerability resides in the Core component of the product.
Risk and Exploitability
The CVSS 3.1 score of 6.0 classifies this flaw as a moderate severity vulnerability. The attack vector is local, with a low complexity requirement, and high privileges are needed to exploit it. No public exploitation has been reported, and the issue is not listed in the CISA KEV catalog. The EPSS score of < 1% indicates a very low probability of exploitation. Nonetheless, environments where host accounts used to run VirtualBox possess excessive privileges face a moderate risk.
OpenCVE Enrichment