Executive brief
Oracle VM VirtualBox is virtualization software that allows users to run multiple operating systems on a single computer. A vulnerability in the Core component allows a high-privileged attacker with local access to cause the application to hang or crash, disrupting virtual machine operations. While an attacker must have elevated privileges on the host system, the scope of impact extends beyond VirtualBox itself to potentially affect other products running within virtual machines.
Technical details
This is a denial-of-service vulnerability in Oracle VM VirtualBox's Core component affecting version 7.2.14 and other version 7.x releases. The vulnerability is exploitable locally (AV:L) by a high-privileged attacker (PR:H) without user interaction, requiring no complex attack conditions (AC:L). Successful exploitation results in a hang or crash (complete DoS) of VirtualBox, with impact scope extending beyond the affected product to potentially impact guest operating systems and workloads. The fix/patch status and exact root cause are not detailed in available references.
Affected products
- Oracle VM VirtualBox 7.2.14 and other version 7.x
Timeline
- 2026-08-18: disclosed