Executive brief
Oracle VM VirtualBox is virtualization software that runs virtual machines on Windows, Linux, and other operating systems. A local privilege escalation vulnerability allows a low-privileged user with access to a Windows system running VirtualBox to gain complete control over the virtualization platform and all virtual machines running on it.
Technical details
This is a local privilege escalation vulnerability in the Core component of Oracle VM VirtualBox affecting version 7.2.16 on Windows hosts only. The vulnerability is easily exploitable by a low-privileged attacker with logon access to the infrastructure, requiring no user interaction. Successful exploitation results in complete takeover of VirtualBox and all running virtual machines. The CVSS 3.1 score of 7.8 reflects high impact across confidentiality, integrity, and availability. Patches are expected to be available from Oracle.
Affected products
- Oracle VM VirtualBox 7.2.16
Timeline
- 2026-09-15: disclosed