Core Vulnerability in Oracle VM VirtualBox Affects Oracle Virtualization
CVE-2025-62589

8.2HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 October 2025

What is CVE-2025-62589?

An exploit in Oracle VM VirtualBox allows high-privileged attackers with access to the infrastructure where VirtualBox operates to compromise the platform. Supported versions 7.1.12 and 7.2.2 are specifically impacted. While the exploit targets Oracle VM VirtualBox, its repercussions can extend to other products as well. Successful exploitation could lead to an attacker taking over the Oracle VM VirtualBox environment, compromising confidentiality, integrity, and availability of its hosted virtual machines.

Affected Version(s)

Oracle VM VirtualBox 7.1.12

Oracle VM VirtualBox 7.2.2

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-62589 : Core Vulnerability in Oracle VM VirtualBox Affects Oracle Virtualization