Executive brief
A vulnerability in Oracle VM VirtualBox could allow a user with limited access to the host computer to compromise the virtualization software. If a legitimate user is tricked into performing a specific action, the attacker could delete or modify critical data and cause the software to crash or become partially unavailable. This could disrupt business operations and compromise the integrity of virtualized environments.
Technical details
A vulnerability exists in the Core component of Oracle VM VirtualBox version 7.2.12. The flaw is categorized as easily exploitable by a low-privileged attacker with local logon access to the infrastructure where VirtualBox is running. Exploitation requires human interaction from a person other than the attacker (User Interaction: Required). Successful exploitation allows an attacker to gain unauthorized creation, deletion, or modification access to critical data or all data accessible by VirtualBox, as well as the ability to cause a partial denial of service. The CVSS 3.1 vector is AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L, indicating high integrity impact and low availability impact.
Affected products
- Oracle VM VirtualBox 7.2.12
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update published