Impact
Oracle VM VirtualBox 7.2.16 contains a flaw that allows an attacker with local administrative privileges on the host to read confidential data stored within the VirtualBox environment. The vulnerability arises from improper access control within the core component, enabling the attacker to bypass expected confines and access a subset of VirtualBox‑managed data. The impact is limited to confidentiality, with no direct integrity or availability consequences reported. The flaw stems from CWE-284, improper access control.
Affected Systems
Oracle Corporation’s Oracle VM VirtualBox 7.2.16 running on a host system exposed to local administrative users.
Risk and Exploitability
The CVSS v3.1 base score of 3.2 indicates a low‑severity risk, primarily affecting confidentiality and requiring local access (attack vector Local, low complexity). The EPSS score of less than 1 % signifies a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw leads to unauthorized read access and can impact additional products when VirtualBox is integrated with other services, any environment where privileged local accounts exist should treat the issue as a low‑severity but actionable threat.
OpenCVE Enrichment