Executive brief
Oracle VM VirtualBox is a virtualization platform used to run multiple operating systems on a single computer. A high-privileged attacker with access to the host infrastructure can exploit a vulnerability in the Core component to take over VirtualBox and potentially compromise other systems running on it. This could lead to loss of data, service disruption, and compromise of all virtual machines under that host's control.
Technical details
A privilege escalation vulnerability exists in the Core component of Oracle VM VirtualBox version 7.2.14. The vulnerability is difficult to exploit and requires high-level privileges and local access (logon to the infrastructure where VirtualBox executes). Successful exploitation allows an attacker to achieve complete takeover of the VirtualBox system with impacts to confidentiality, integrity, and availability. The vulnerability has scope change, meaning an attack on VirtualBox can significantly impact additional products and systems. Patches are available from Oracle; users should update to the latest supported version.
Affected products
- Oracle VM VirtualBox 7.2.14
Timeline
- 2026-08-18: disclosed