Executive brief
Oracle VM VirtualBox is virtualization software that runs virtual machines on physical hosts. A vulnerability in its Core component allows a high-privilege local attacker to crash the virtualization platform, causing downtime and disrupting all virtual machines running on the affected host. This requires local access and administrative privileges, limiting the attack surface to insider threats or compromised accounts with high-level system access.
Technical details
This is a denial-of-service vulnerability in the Core component of Oracle VM VirtualBox version 7.2.14, triggered by a local attack vector requiring high privilege (logon to the infrastructure). The vulnerability allows an authenticated high-privilege attacker to cause a hang or crash (complete DOS) of the VirtualBox process. The attack has low complexity and no user interaction required. The CVSS 3.1 score of 4.4 reflects impact limited to availability with no confidentiality or integrity compromise. Patches are expected from Oracle's regular security updates.
Affected products
- Oracle VM VirtualBox 7.2.14
Timeline
- 2026-08-18: disclosed