Impact
This vulnerability in Oracle VM VirtualBox 7.2.16 allows a low‑privileged attacker that has logged onto the Windows host to take full control of the VirtualBox process, resulting in a compromise of the virtualization platform. The impact includes loss of confidentiality, integrity, and availability of all virtual machines, stemming from an improper access control flaw in the core component.
Affected Systems
Oracle Corporation’s Oracle VM VirtualBox version 7.2.16 on Windows hosts.
Risk and Exploitability
The CVSS 3.1 base score is 7.8, while the EPSS score of 0.00127 indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local and requires the attacker to have a user account on the Windows host. Successful exploitation leads to full takeover of VirtualBox without user interaction. Even with a low exploitation likelihood, the potential impact remains high, so the overall risk is considered moderate to high for systems running the affected version, especially where local users have elevated privileges.
OpenCVE Enrichment