Impact
The vulnerability is a local privilege escalation (CWE‑269) in the Core component of Oracle VM VirtualBox 7.2.16. An attacker who has a low‑privileged account logged into the host system can exploit the flaw to take control of the VirtualBox process. This can lead to full compromise of the VirtualBox instance, giving the attacker the ability to read, modify, or delete any data handled by VirtualBox and to interfere with its normal operation. The impact is limited to the VirtualBox environment and does not extend to the entire host.
Affected Systems
Oracle Corporation’s Oracle VM VirtualBox 7.2.16 is affected. The Core component of this product is impacted. No other versions or component variants are listed in the vulnerability description.
Risk and Exploitability
The CVSS 3.1 base score of 7.8 indicates high severity. The EPSS score is below 1%, showing low likelihood of current widespread exploitation. Attackers must already have local access to the host and can bind to the Vulnerable VirtualBox instance. Because the vulnerability is local and requires low privileges, it affords a moderate to high risk for systems running VirtualBox with inadequate isolation, but the low EPSS suggests that exploitation is currently unlikely.
OpenCVE Enrichment