Impact
Oracle VM VirtualBox 7.2.14 contains a vulnerability in its core component that allows a local attacker with high privileges to compromise the VirtualBox process. Successful exploitation grants the attacker the ability to update, insert or delete VirtualBox‑accessible data, read a subset of that data, and trigger a partial denial of service. The weakness originates from improper access control (CWE‑284), enabling operations beyond the intended scope.
Affected Systems
This issue affects Oracle Corporation’s Oracle VM VirtualBox version 7.2.14. No other versions are listed as affected in the CNA data.
Risk and Exploitability
The CVSS 3.1 base score is 5.7, indicating moderate severity with impacts on confidentiality, integrity and availability. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires local access and high privileges, making remote exploitation unlikely. The scope change indicates that a successful compromise can affect additional components beyond the primary VirtualBox process.
OpenCVE Enrichment