Executive brief
Oracle VM VirtualBox is a widely-used virtualization platform that allows organizations to run multiple operating systems on a single physical machine. This vulnerability allows a low-privileged user with local access to the host system to gain complete control over VirtualBox, potentially compromising all virtual machines and their data. The impact extends beyond VirtualBox itself, affecting the security of guest operating systems and any workloads running within them.
Technical details
This is a local privilege escalation vulnerability in the Core component of Oracle VM VirtualBox. The vulnerability is difficult to exploit and requires the attacker to have low-level logon access to the infrastructure hosting VirtualBox, with no user interaction required. Successful exploitation can result in complete takeover of VirtualBox, with scope change indicating that impacts extend to other products and systems running within the hypervisor. The CVSS vector reflects high impact across confidentiality, integrity, and availability. Patches should be available from Oracle; users should upgrade from the affected version 7.2.14 to a patched release.
Affected products
- Oracle VM VirtualBox 7.2.14
Timeline
- 2026-08-18: disclosed