Executive brief
A vulnerability in Oracle VM VirtualBox, a popular virtualization tool used to run multiple operating systems on a single computer, allows a user with low-level access to the host system to crash the software. This can lead to a complete denial of service, causing virtual machines to hang or stop working unexpectedly. While it does not allow for data theft, it can disrupt business operations and service availability.
Technical details
A vulnerability in the Core component of Oracle VM VirtualBox version 7.2.12 allows a low-privileged attacker with local logon access to the host infrastructure to compromise the application's availability. The flaw is categorized as easily exploitable and does not require user interaction. Successful exploitation results in a frequently repeatable crash or a system hang, leading to a complete denial of service (DoS) for the VirtualBox environment. No impacts to confidentiality or integrity were reported. Users should refer to the Oracle July 2026 Critical Patch Update for remediation details.
Affected products
- Oracle VM VirtualBox 7.2.12
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 Critical Patch Update.
- 2026-07-21: disclosed