HomeSecurityMultiple flaws in Oracle VM VirtualBox

Multiple flaws in Oracle VM VirtualBox

Oracle has disclosed multiple critical flaws in its Oracle VM VirtualBox, potentially allowing attackers to gain complete control of the VirtualBox environment.

See also: Oracle releases patches for October 2025

Oracle

These flaws, detailed in the October 2025 Critical Update (CPU) , affect the core component of VirtualBox versions 7.1.12 and 7.2.2 , allowing local attackers with elevated privileges to compromise confidentiality, integrity, and availability with catastrophic consequences.

The disclosure highlights ongoing risks in virtualization platforms, where even local access can lead to wider system impacts due to changes in scope.

Experts warn that these vulnerabilities could facilitate full-scale takeover scenarios, making immediate patching essential for users who rely on VirtualBox for development, testing, and secure isolation. No evidence of active exploitation has yet emerged, but the high CVSS scores underscore the urgency.

See also: Oracle E-Business Suite: New RCE vulnerability exposes data

Multiple flaws in Oracle VM VirtualBox

Oracle's advisory emphasizes that while the exploit requires elevated privileges and local access, the potential for unauthorized data access and denial-of-service attacks remains a serious threat.

The October 2025 CPU patch addresses nine specific CVEs in the VirtualBox kernel, all classified as local exploits without remote authentication. These issues stem from improper permission handling and unsafe actions, allowing attackers with a connection to the infrastructure to escalate control.

The most severe ones, including CVE-2025-62587 through CVE-2025-62590 and CVE-2025-62641, have a CVSS 3.1 base score of 8.2, indicating high risk due to low attack complexity and altered scope.

Lower severity flaws, such as CVE-2025-61759 and CVE-2025-62591 to 62592, are rated 6.0 to 6.5, focusing on confidentiality violations without disrupting integrity or availability.

See also: PoC Exploit published for zero-day in Oracle E-Business Suite

Multiple flaws in Oracle VM VirtualBox

All flaws require local access, but can be spread beyond VirtualBox due to scope changes. Successful exploitation could lead to a complete takeover of the VirtualBox environment, exposing sensitive virtual machine data and allowing malware to persist on isolated systems.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS