CVE-2025-30712
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2025-30712 is a high-privileged vulnerability affecting Oracle VM VirtualBox version 7.1.6. This issue, situated within the product's core component, is easily exploitable by attackers with logon access to the affected infrastructure. The scope of damage goes beyond Oracle VM VirtualBox, as additional products may also be significantly impacted. A successful exploit can lead to the unauthorized creation, deletion, or modification of critical data, and grant attackers complete access to all Oracle VM VirtualBox accessible data. Moreover, partial denial of service (DoS) attacks against Oracle VM VirtualBox are also possible. The CVSS Base Score is 8.1, indicating significant risks to confidentiality, integrity, and availability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Oracle VM Virtualbox
Affected Vendors
- Oracle