Oracle VM VirtualBox Core Component Privilege Escalation Vulnerability

Vulnerability

A vulnerability has been identified in the Oracle VM VirtualBox product, specifically in the Core component. This issue affects versions 7.1.12 and 7.2.2. The vulnerability allows a high-privileged attacker with access to the infrastructure where Oracle VM VirtualBox is running to compromise the application. Although the vulnerability is contained within Oracle VM VirtualBox, successful exploitation could significantly impact other products, leading to a scope change. Exploitation of this vulnerability could result in a complete takeover of Oracle VM VirtualBox.

Impact

Exploitation of this vulnerability allows for a complete takeover of Oracle VM VirtualBox. However, due to the scope change, attacks could also significantly impact additional products.

Added: Oct 21, 2025, 8:46 PM
Updated: Oct 21, 2025, 10:01 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
7.5
exploitability
2.8
remediation
0.0
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.