Executive brief
Oracle VM VirtualBox is virtualization software that runs virtual machines on physical servers. A high-privileged local attacker with access to the host system can exploit a vulnerability in the Core component to crash VirtualBox, read sensitive data within it, and modify or delete data. This could disrupt critical virtual machine operations and compromise the confidentiality and integrity of workloads running in the virtual environment.
Technical details
This is a privilege escalation vulnerability in Oracle VM VirtualBox's Core component affecting version 7.2.14. The vulnerability requires high privileges and local logon access to the host system; it cannot be exploited remotely. Successful exploitation allows an attacker to cause denial of service (hang or crash of VirtualBox), read a subset of VirtualBox-accessible data, and update, insert, or delete some data. The attack has scope change, meaning the impact extends beyond VirtualBox itself to potentially affect additional products. No patch information was available at the time of advisory publication.
Affected products
- Oracle VM VirtualBox 7.2.14
Timeline
- 2026-08-18: disclosed