Executive brief
A security vulnerability exists in Oracle VM VirtualBox, a popular virtualization tool used to run multiple operating systems on a single computer. A highly privileged attacker with access to the host system could exploit this flaw to take full control of the VirtualBox environment. Because this issue involves a 'scope change,' a successful attack could potentially allow the intruder to move beyond the virtual machine and impact the underlying host or other connected systems.
Technical details
This vulnerability is classified as improper privilege management (CWE-269) within the VMSVGA device component of Oracle VM VirtualBox version 7.2.8. It is a local attack requiring high privileges (PR:H) and high complexity (AC:H), meaning the attacker must already have significant access to the infrastructure where VirtualBox is executing. The exploit results in a scope change (S:C), indicating that an attacker can break out of the virtualization layer to impact the host or other virtualized products. Successful exploitation grants full control over the VirtualBox process, impacting confidentiality, integrity, and availability.
Affected products
- Oracle VM VirtualBox 7.2.8
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle via NVD and security alert.