CVE-2025-21533

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jan 21, 2025
Updated: Jan 22, 2025
CWE ID 863

Summary

CVE-2025-21533 is a vulnerability affecting Oracle VM VirtualBox, a component of Oracle Virtualization. Affected versions are prior to 7.0.24 and 7.1.6. This issue allows a low-privileged attacker with access to the infrastructure where Oracle VM VirtualBox runs to compromise the software. Successfully exploited vulnerabilities can result in unauthorized access to sensitive data or complete access to all Oracle VM VirtualBox accessible data, posing a significant confidentiality risk. The vulnerability receives a CVSS 3.1 Base Score of 5.5. Attackers can exploit this remotely, making it easily exploitable and a potential threat to infrastructure security.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share