Impact
A flaw in the core component of Oracle VM VirtualBox 7.2.16 allows a low‑privileged user on a Windows host to take control of the VirtualBox process. The vulnerability grants an attacker complete compromise of the VirtualBox environment, affecting confidentiality, integrity, and availability. The CVSS vector for this issue is AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, which gives a high severity rating.
Affected Systems
Oracle Corporation’s VM VirtualBox version 7.2.16 running on Windows hosts is affected. No other versions, platforms, or operating systems are listed as impacted, and the flaw does not apply to non‑Windows hosts.
Risk and Exploitability
The CVSS base score of 7.8 indicates high severity. The EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not included in the CISA KEV catalog. The likely attack vector is local: an attacker who can log on to the host machine or otherwise obtain local user privileges can exploit the flaw to hijack the VirtualBox process.
OpenCVE Enrichment