Impact
This vulnerability is a local privilege escalation flaw in Oracle VM VirtualBox 7.2.14. An attacker who has high privileged logon access to the host where VirtualBox runs can exploit the flaw to compromise the VirtualBox process itself, gaining unauthorized read access to all data that VirtualBox manages. The risk to confidentiality is high as the attacker can read critical information, and the vulnerability also allows the attacker to alter the scope of impact, potentially affecting other products that rely on VirtualBox.
Affected Systems
The affected system is Oracle Corporation's Oracle VM VirtualBox, specifically version 7.2.14 of the Core component.
Risk and Exploitability
The CVSS base score of 6.0 indicates medium severity, while the EPSS score is <1%, indicating a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local; an adversary needs high privileged user access on the host machine and the ability to run binaries. Once exploited, the scope changes from the virtual machine to the host platform, granting the attacker the ability to read protected files and potentially subvert the virtualization environment. Despite moderate scoring, the confidentiality impact is significant and the flaw is easily exploitable by a high privileged user.
OpenCVE Enrichment