Vulnerability in Oracle VM VirtualBox by Oracle
CVE-2025-30725

6.7MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2025

Summary

A vulnerability exists in Oracle VM VirtualBox, specifically in the core component, which affects version 7.1.6. This vulnerability is challenging to exploit but can allow a high-privileged attacker who has already logged onto the infrastructure where Oracle VM VirtualBox operates to exploit the software. If successfully attacked, the vulnerabilities can lead to a denial of service (DOS) by causing repeated crashes or hangs of the application. Moreover, unauthorized access can enable attackers to update, insert, or delete data as well as gain read access to sensitive data within Oracle VM VirtualBox.

Affected Version(s)

Oracle VM VirtualBox 7.1.6

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.