Impact
A vulnerability exists in the core component of Oracle VM VirtualBox that allows an attacker who has simply logged onto the same infrastructure to take control of the VirtualBox process. Because the vulnerability can be exploited locally without any pre‑existing authentication, it is considered easily exploitable, although the attacker still must interact with a user other than themselves to initiate the attack. When successfully exploited, the impact is severe, affecting confidentiality, integrity, and availability of the VirtualBox instance and potentially other applications that rely on it, as noted by the scope change.
Affected Systems
The affected product is Oracle VM VirtualBox version 7.2.16 from Oracle Corporation. No other vendors or product variants are listed as affected in the current advisory.
Risk and Exploitability
The CVSS base score is 8.6, indicating a high severity vulnerability. EPSS is reported as less than 1 %, meaning the probability of exploitation is currently very low but not zero. The vulnerability is not included in the CISA KEV catalog. Exploitation requires the attacker to have local logon access to the host machine where VirtualBox runs and a human interaction from a user other than the attacker to trigger the exploit. Because of its local nature and the need for user interaction, the immediate threat to environments with strict access controls is mitigated, but once those controls are bypassed, the potential for total compromise remains high. The scope change indicates that exploitation could spill over to other applications on the same host or connected virtual network. Overall, the risk remains high for any environment running Oracle VM VirtualBox 7.2.16 that exposes the host to local users.
OpenCVE Enrichment