Executive brief
Oracle VM VirtualBox is virtualization software that runs virtual machines on host computers. This vulnerability allows a privileged local attacker to crash VirtualBox and render virtual machines unavailable, disrupting operations and potentially affecting multiple systems. The attack requires administrative-level access to the host system where VirtualBox is running.
Technical details
This vulnerability in the VirtualBox Core component is an easily exploitable denial-of-service flaw requiring high privilege (root/administrative) access and local logon to the infrastructure. The attack vector is local (AV:L) with no user interaction required. Successful exploitation causes a hang or crash of VirtualBox (complete availability impact), with scope change indicating secondary impact on additional products. The CVSS 3.1 vector (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H) reflects a base score of 6.0 with no confidentiality or integrity impact, only availability.
Affected products
- Oracle VM VirtualBox 7.2.14
Timeline
- 2026-08-18: disclosed