PT-2025-42981 · Oracle+1 · Virtualbox+1

Published

2025-10-21

·

Updated

2026-01-12

·

CVE-2025-61760

CVSS v3.1

7.5

High

VectorAV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle VM VirtualBox versions 7.1.12 and 7.2.2
Description A difficult-to-exploit issue exists in the Oracle VM VirtualBox product, specifically within the Core component. A low-privileged attacker with access to the system where Oracle VM VirtualBox is running can compromise the software. Exploitation requires interaction from another person and may impact other products. Successful exploitation can lead to a takeover of Oracle VM VirtualBox. The issue involves a stack buffer overflow in the virtioCoreR3VirtqInfo function of the VBoxManage debugvm command.
Recommendations Update Oracle VM VirtualBox to a version that addresses this issue.

Fix

Improper Access Control

Stack Overflow

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-10635
CVE-2025-61760

Affected Products

Virtualbox
Red Os