Impact
The vulnerability resides in the core component of Oracle VM VirtualBox version 7.2.14. It enables an attacker who already has a low‑privileged account on a host that runs VirtualBox to compromise the VirtualBox process, leading to full takeover. Successful exploitation results in loss of confidentiality, integrity, and availability of the VirtualBox installation. Because the vulnerability has a scope change, a compromised VirtualBox instance may also be used to affect other products running on the same infrastructure.
Affected Systems
Oracle VM VirtualBox 7.2.14, a product of Oracle Corporation. Only this specific major/minor version is affected.
Risk and Exploitability
The CVSS 3.1 base score of 7.8 indicates high severity, with high attack complexity and local access required. The EPSS score is reported as <1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation data. Nonetheless, local attackers with low privileges can exploit it, and because the vulnerability's scope is changed, the compromise could spread to other applications on the infrastructure.
OpenCVE Enrichment