Executive brief
Oracle VM VirtualBox is virtualization software that runs virtual machines on a host system. A vulnerability in its Core component allows a local attacker with system access to compromise the virtualization platform through social engineering or user interaction, potentially gaining full control over all virtual machines and the host system. This could impact business continuity, customer data isolation, and the integrity of workloads running on the virtualized infrastructure.
Technical details
This is a local privilege escalation vulnerability in the Oracle VM VirtualBox Core component, affecting version 7.2.14. The vulnerability requires an unauthenticated attacker with local logon access to the infrastructure where VirtualBox is running, combined with user interaction from a legitimate user (UI:R). The attack vector is local (AV:L) with low complexity (AC:L), meaning exploitation is straightforward once the attacker has system access. Successful exploitation results in complete compromise of the VirtualBox instance with scope change, affecting confidentiality, integrity, and availability. The vulnerability can take over the VirtualBox process and potentially impact other systems on the infrastructure. Patches are expected from Oracle's security updates.
Affected products
- Oracle VM VirtualBox 7.2.14
Timeline
- 2026-08-18: disclosed