Impact
The Oracle VM VirtualBox core component contains a vulnerability that allows a low‑privileged local user to compromise the VirtualBox runtime without user interaction. If an attacker has logon access to the host, they can read all data exposed by VirtualBox, making the breach a severe confidentiality risk while leaving integrity and availability unaffected. The CVSS 3.1 vector indicates a local attack with low privileges, no user interaction required, and a confidentiality impact rated high.
Affected Systems
Oracle VM VirtualBox version 7.2.14 installed on host systems is vulnerable. Because the flaw has a scope change property, attacks that succeed against VirtualBox can also affect any additional products that interact with VirtualBox.
Risk and Exploitability
The CVSS score of 5.6 labels this vulnerability as moderate. Exploitation requires only local access with low privileges and the attack requires no additional user interaction, suggesting a moderate risk of exploitation in environments where such users exist. The EPSS score is less than 1% and this issue is not listed in the CISA KEV catalog.
OpenCVE Enrichment