CVE-2025-30712

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Apr 15, 2025
Updated: Apr 21, 2025
CWE ID 284

Summary

CVE-2025-30712 is a high-privileged vulnerability affecting Oracle VM VirtualBox version 7.1.6. This issue, situated within the product's core component, is easily exploitable by attackers with logon access to the affected infrastructure. The scope of damage goes beyond Oracle VM VirtualBox, as additional products may also be significantly impacted. A successful exploit can lead to the unauthorized creation, deletion, or modification of critical data, and grant attackers complete access to all Oracle VM VirtualBox accessible data. Moreover, partial denial of service (DoS) attacks against Oracle VM VirtualBox are also possible. The CVSS Base Score is 8.1, indicating significant risks to confidentiality, integrity, and availability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Oracle VM Virtualbox

Affected Vendors

  • Oracle