CVE-2025-62641

Published Oct 21, 2025

Last updated 2 days ago

CVSS high 8.2
Oracle VM VirtualBox

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-62641 is a vulnerability in Oracle VM VirtualBox, specifically affecting versions 7.1.12 and 7.2.2. It exists within the Core component of the Oracle Virtualization product. The vulnerability can be easily exploited by a highly privileged attacker who has logon access to the infrastructure where Oracle VM VirtualBox is running. Successful exploitation of this vulnerability could allow an attacker to take over Oracle VM VirtualBox.

Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Source
secalert_us@oracle.com
NVD status
Analyzed
Products
vm_virtualbox

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.2
Impact score
6
Exploitability score
1.5
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Severity
HIGH

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-267

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.