Privilege Escalation Vulnerability in Oracle VM VirtualBox by Oracle
CVE-2025-62592

6MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 October 2025

What is CVE-2025-62592?

A privilege escalation vulnerability exists in Oracle VM VirtualBox that allows an attacker with sufficient permissions within the infrastructure to compromise the hypervisor. This vulnerability primarily affects versions 7.1.12 and 7.2.2 and can lead to unauthorized access to sensitive information or complete control over data stored within Oracle VM VirtualBox. Attackers can exploit this flaw to significantly impact the security of the virtual environment, potentially affecting other interconnected systems.

Affected Version(s)

Oracle VM VirtualBox 7.1.12

Oracle VM VirtualBox 7.2.2

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-62592 : Privilege Escalation Vulnerability in Oracle VM VirtualBox by Oracle