Executive brief
Oracle VM VirtualBox is virtualization software used to run multiple operating systems on a single computer. A local privilege escalation vulnerability in version 7.2.16 (Windows host only) allows a user with basic system access to take complete control of the virtualization environment, potentially compromising all virtual machines and the host system. An attacker could access or modify sensitive data and disrupt operations across hosted systems.
Technical details
This is a local privilege escalation vulnerability in the Core component of Oracle VM VirtualBox 7.2.16 affecting Windows hosts. The vulnerability is easily exploitable and requires only low-level privileges and logon access (no special authentication bypass required). An attacker with local access can escalate privileges to achieve complete compromise (takeover) of the VirtualBox process and guest virtual machines. The attack vector is local, with low complexity, and does not require user interaction. Patch availability status is not indicated in the advisory.
Affected products
- Oracle VM VirtualBox 7.2.16
Timeline
- 2026-09-15: disclosed