216.73.217.22

CVE-2025-62641

· Published 21/10/2025 20:20 · Modified 21/10/2025 21:15

Labels: CVE-2025-62641 2025-10-21CVE-2025-62641CWE-267[email protected]

Essential information

Published
21/10/2025 20:20
Modified
21/10/2025 21:15
Author
Creator
CVSS
8.2 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
oracle / virtualbox cpe:2.3:a:oracle:virtualbox:7.1.12:*:*:*:*:*:*:*
oracle / virtualbox cpe:2.3:a:oracle:virtualbox:7.2.2:*:*:*:*:*:*:*

References