PT-2025-29664 · Oracle+2 · Virtualbox+2

Published

2025-05-23

·

Updated

2025-10-01

·

CVE-2025-53025

CVSS v3.1

6.0

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle VM VirtualBox version 7.1.10
Description An easily exploitable issue exists in the Core component of Oracle VM VirtualBox. A high-privileged attacker with access to the infrastructure where Oracle VM VirtualBox executes can compromise the software. Successful exploitation may lead to unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. Attacks may significantly impact additional products.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

ALT-PU-2025-9918
BDU:2025-08874
CVE-2025-53025
ZDI-25-598

Affected Products

Alt Linux
Virtualbox
Red Os