Impact
A local vulnerability in the Core component of Oracle VM VirtualBox 7.2.14 allows an attacker who has local presence on the host machine to obtain the privileges of the logged‑in user after a separate user interacts with the system. The flaw lets the attacker take full control of VirtualBox, potentially affecting the host’s confidentiality, integrity, and availability, and the vector label confirms that no privilege is required to launch the initial attack. Successful exploitation raises the attacker's authority to that of a normal local user, enabling further malicious activity on the host.
Affected Systems
Oracle VM VirtualBox version 7.2.14. No other versions or variants are listed as affected.
Risk and Exploitability
With a CVSS base score of 8.6, the issue is high severity, but its local attack surface and the need for user interaction result in a low EPSS (<1%) and no current listing in the CISA KEV catalog. The vulnerability can lead to a scope change, so an affected machine can become a vector for compromising other components, yet the likelihood of immediate exploitation remains modest without deliberate involvement of a second user.
OpenCVE Enrichment