Executive brief
Oracle VM VirtualBox is a virtualization platform used to run multiple virtual machines on a single physical server. A vulnerability in the Core component allows a high-privileged local attacker to partially disrupt the service, potentially affecting the availability of hosted virtual machines. The vulnerability is localized to VirtualBox but may impact other products running on the same infrastructure.
Technical details
This is a local privilege escalation vulnerability in the Core component of Oracle VM VirtualBox 7.2.16. The vulnerability requires high privileges and local logon access to the host system where VirtualBox is running, with no user interaction needed. A successful exploit can cause a partial denial of service (partial DOS) affecting the availability of VirtualBox. The scope is marked as changed, indicating that while the flaw is in VirtualBox, attacks may impact other software running on the same host. A patch is expected from Oracle's September 2026 security update.
Affected products
- Oracle VM VirtualBox 7.2.16
Timeline
- 2026-09-15: disclosed