Impact
The vulnerability exists in the Core component of Oracle VM VirtualBox 7.2.14. If a high‑privileged attacker has logged on to the host system, they can exploit this flaw to modify, insert, or delete VirtualBox‑accessible data and also to read protected subsets of that data. The impact is limited to confidentiality and integrity; denial of service is not expected, which is reflected in the CVSS base score of 3.4.
Affected Systems
The only affected product is Oracle Corporation’s Oracle VM VirtualBox version 7.2.14. No other versions or components are listed as vulnerable.
Risk and Exploitability
The CVSS score of 3.4 indicates low severity. The attack vector is local and necessitates high privilege. The EPSS score suggests a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Because no official patch or workaround has been released, the primary mitigation is to restrict privileged access and monitor VirtualBox configuration and data files for unauthorized changes.
OpenCVE Enrichment