Impact
The vulnerability in Oracle VM VirtualBox allows a high‑privileged local attacker to compromise the VirtualBox instance, granting unauthorized access to critical data. Because the flaw resides in core components, successful exploitation can lead to broader impact across other products that rely on VirtualBox, as described by the reported scope change. The attack does not provide remote execution, but it facilitates sensitive information exposure through the compromised VirtualBox environment.
Affected Systems
Oracle Corporation’s Oracle VM VirtualBox version 7.2.14 is affected. No other product versions are identified in the data.
Risk and Exploitability
With a CVSS 3.1 base score of 5.3 and an AV:L, AC:H, PR:H vector, the vulnerability is of moderate severity and requires local access coupled with high privileges to exploit. The EPSS score of < 1% indicates a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog. Because the flaw is difficult to exploit and confined to a local environment, the overall risk is lower than for remote‑exposed flaws, yet the potential confidentiality impact warrants timely remediation.
OpenCVE Enrichment