CVE-2025-62641: High severity Oracle VM VirtualBox vulnerability
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62641?
CVE-2025-62641 has been classified as an easily exploitable vulnerability that poses a significant risk to Oracle VM VirtualBox users.
How do I fix CVE-2025-62641?
To fix CVE-2025-62641, apply the latest security patches provided by Oracle for Oracle VM VirtualBox version 7.1.12 and 7.2.2.
Who is affected by CVE-2025-62641?
CVE-2025-62641 affects users of Oracle VM VirtualBox versions 7.1.12 and 7.2.2 that are running on vulnerable infrastructure.
Can CVE-2025-62641 be exploited remotely?
CVE-2025-62641 requires a high privileged attacker with logon access to the infrastructure where Oracle VM VirtualBox runs, making it less likely to be exploited remotely.
What are the potential impacts of CVE-2025-62641?
The potential impacts of CVE-2025-62641 may include unauthorized access and control over the Oracle VM VirtualBox environment.