PT-2025-4292 · Oracle+2 · Virtualbox+2

Yuhao Jiang

·

Published

2025-01-21

·

Updated

2025-10-10

·

CVE-2025-21571

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions Oracle VM VirtualBox versions prior to 7.0.24 Oracle VM VirtualBox versions prior to 7.1.6
Description The issue allows a high-privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle VM VirtualBox accessible data, as well as unauthorized read access to a subset of Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service of Oracle VM VirtualBox. The vulnerability is related to the Core component of Oracle VM VirtualBox and may significantly impact additional products.
Recommendations For Oracle VM VirtualBox versions prior to 7.0.24, update to version 7.0.24 or later. For Oracle VM VirtualBox versions prior to 7.1.6, update to version 7.1.6 or later. As a temporary workaround, consider restricting access to the Core component of Oracle VM VirtualBox to minimize the risk of exploitation.

Fix

DoS

LPE

Incorrect Permission

Weakness Enumeration

Related Identifiers

ALT-PU-2025-12585
ALT-PU-2025-12587
ALT-PU-2025-12588
ALT-PU-2025-12589
ALT-PU-2025-12590
ALT-PU-2025-6602
BDU:2025-03464
CVE-2025-21571
MGASA-2025-0027

Affected Products

Alt Linux
Virtualbox
Red Os