Executive brief
Oracle VM VirtualBox is virtualization software that runs virtual machines on enterprise servers. A flaw in its core component allows a low-privileged local user to crash VirtualBox or corrupt data within virtual machines, disrupting operations and potentially causing data loss.
Technical details
This is a local privilege escalation and integrity/availability vulnerability in the Core component of Oracle VM VirtualBox version 7.2.16. The vulnerability requires local logon access and low privileges; no user interaction is needed. A successful exploit allows an attacker to cause denial of service (hang or crash) of the VirtualBox process and modify accessible data within the virtualized environment. The CVSS 3.1 score of 6.1 reflects medium severity with low integrity and high availability impacts. Patches should be available through Oracle's security updates.
Affected products
- Oracle VM VirtualBox 7.2.16
Timeline
- 2026-09-15: disclosed