Impact
Vulnerability in the core component of Oracle VM VirtualBox publicly allows an unauthenticated attacker with Remote Desktop Protocol network access to read critical data and perform update, insert or delete operations on VirtualBox‑exposed data. The flaw results in high confidentiality impact and lower integrity impact as outlined by the CVSS 3.1 vector, indicating that an attacker can not only observe sensitive information but also alter it. The weakness can be classified as improper access control.
Affected Systems
Oracle VM VirtualBox version 7.2.14 is specifically affected. No other versions or products are listed as impacted in the available data.
Risk and Exploitability
The CVSS base score of 8.2 classifies this as high‑severity. Exploitability is considered high because the attack requires only unprivileged network access with no user interaction and no local authentication. The EPSS score is reported as less than 1%, suggesting a relatively low probability of exploitation in the wild, yet the ease of exploitation described in the advisory indicates that successful attacks are plausible. The vulnerability is not listed in CISA’s KEV catalog, but the potential for unauthorized data access and modification makes it a serious threat if left unpatched.
OpenCVE Enrichment