Impact
The flaw exists within the Core component of Oracle VM VirtualBox version 7.2.14, allowing an attacker who already possesses high privileged access to the host infrastructure to fully compromise the VirtualBox installation. The vulnerability is locally exploitable, requires no network access or user interaction, and can lead to complete loss of confidentiality, integrity, and availability of the VirtualBox service, with a potential scope change affecting additional products on the same host.
Affected Systems
Oracle VM VirtualBox 7.2.14, delivered as part of the Oracle Virtualization platform, is the only explicitly affected version listed in the advisory. No other product versions are currently identified as impacted.
Risk and Exploitability
The CVSS v3.1 base score of 8.2 indicates a high‑severity issue; the exploitability vector (AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H) reflects a local attack that requires a user to be already privileged. The EPSS score of < 1% suggests a very low probability of exploitation in the wild, and the vulnerability is not catalogued in the CISA KEV list. Nevertheless, in environments where privileged users exist on the host running VirtualBox, the risk of a successful exploitation carries significant impact, potentially allowing the attacker to take full control over the VirtualBox service and affect other services due to the indicated scope shift.
OpenCVE Enrichment