Impact
The vulnerability is a local access flaw (CWE-284) that allows an unauthenticated user who has already logged on to the host system to compromise Oracle VM VirtualBox. Successful exploitation can lead to the creation, deletion or modification of critical VirtualBox data, unauthorized reading of a subset of data, and the ability to trigger a partial denial of service. The CVSS vector (AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L) indicates moderate to high impact on confidentiality, integrity, and availability.
Affected Systems
Oracle VM VirtualBox version 7.2.14 is the only affected release. The likely impact on additional products is inferred from the scope change flag in the CVSS vector, but the primary target is the VirtualBox installation itself.
Risk and Exploitability
The estimated CVSS of 7.7 classifies the vulnerability as high severity. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA KEV, suggesting it is not a known widely exploited flaw yet. The requirement for local access and human interaction between the attacker and another party suggests that the likelihood of exploitation depends on the environment’s security controls, and in environments where privileged users have broad access to VirtualBox hosts, the risk is significant.
OpenCVE Enrichment