Executive brief
Oracle VirtualBox is a virtualization platform that allows organizations to run multiple operating systems on a single physical host. A privilege escalation vulnerability in the Core component could allow a low-privileged user with local system access to take control of VirtualBox and any virtual machines running on it, potentially exposing sensitive business operations and data.
Technical details
This is a local privilege escalation vulnerability in Oracle VirtualBox Core component affecting version 7.2.16. The vulnerability requires local attacker access with low privileges and user interaction from another person, combined with difficult exploitation conditions. The attack vector is local (AV:L) with high complexity (AC:H), and successful exploitation enables complete compromise of the VirtualBox system with scope change (affecting other products). The CVSS 3.1 vector (AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H) reflects impacts to confidentiality, integrity, and availability of the virtualization host and dependent systems.
Affected products
- Oracle VirtualBox 7.2.16
Timeline
- 2026-09-15: disclosed