Impact
Oracle VM VirtualBox version 7.2.14 contains a flaw in its core component that can be exploited by a user who already has a logon to the host running VirtualBox. The vulnerability requires the attacker to be a high privileged local user and is difficult to exploit, but a successful attack would give the attacker comprehensive control over the VirtualBox instance, allowing full compromise of the product’s confidentiality, integrity and availability. The flaw also carries a scope change risk, potentially affecting other dependent products on the same host.
Affected Systems
Oracle Corporation’s Oracle VM VirtualBox, specifically the 7.2.14 release. No other products or versions are listed as affected.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 signals medium to high severity; its Local attack vector (AV:L) combined with the required high privilege (PR:H) means the attack can only be carried out in an environment where the attacker has already logged on. The EPSS score is < 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it is not yet actively exploited. Nonetheless, because the flaw can change the scope of the attack and lead to complete takeover of VirtualBox, the potential impact is significant if the conditions are met.
OpenCVE Enrichment