Impact
The Oracle VM VirtualBox Core component version 7.2.16 on Windows hosts contains an easily exploitable local vulnerability that allows a low‑privileged user who can log on to the host to compromise the VirtualBox process. Successful exploitation can result in a complete takeover of VirtualBox, potentially exposing the sensitive configuration and data stored by the virtualization environment. The flaw is rated as a privilege escalation weakness (CWE‑269) and has a CVSS 3.1 base score of 7.8, indicating significant confidentiality, integrity and availability impact.
Affected Systems
This vulnerability applies only to Oracle VM VirtualBox version 7.2.16 running on Windows hosts. No other platforms or versions are listed as affected. The official CPE indicates the affected product as Oracle VM VirtualBox 7.2.16.
Risk and Exploitability
The attack requires a local user account on the Windows host. The EPSS score of less than 1 % suggests that exploitation attempts are currently infrequent. The CVSS score indicates a high‑severity impact if the flaw is leveraged, and the vulnerability is not yet in the CISA KEV catalog. A local attacker can thus elevate privileges within the VirtualBox process and compromise its configuration and virtual machine data.
OpenCVE Enrichment