Vulnerability in Oracle VM VirtualBox Product by Oracle
CVE-2025-30712

8.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2025

Summary

A vulnerability exists within the Oracle VM VirtualBox product of Oracle Virtualization, specifically in its Core component. This flaw allows a high-privileged attacker with access to the infrastructure hosting Oracle VM VirtualBox to potentially compromise the application. While primarily impacting Oracle VM VirtualBox, successful exploitation can lead to unauthorized creation, deletion, or modification of critical data, along with complete access to all VM-accessible data. Furthermore, attackers could initiate a partial denial of service, affecting the availability of Oracle VM VirtualBox services.

Affected Version(s)

Oracle VM VirtualBox 7.1.6

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.