PT-2025-43004 · Oracle+1 · Virtualbox+1
Published
2025-10-21
·
Updated
2025-12-16
·
CVE-2025-62592
CVSS v3.1
6.0
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle VM VirtualBox versions 7.1.12 and 7.2.2
Description
An issue exists in the
qemuFwCfgMmioRead function within the Box/Devices/PC/DevQemuFwCfg.cpp component of Oracle VM VirtualBox. This relates to an integer overflow condition. Exploitation may allow an attacker to gain unauthorized access to protected information. The vulnerability is easily exploitable and requires high privileges to compromise Oracle VM VirtualBox. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. The issue was identified during analysis of the QemuRamFB component, which allows reading an unlimited amount of memory outside of the array bounds.Recommendations
Versions prior to 7.1.12 and 7.2.2 are affected.
Update to a newer version to address the vulnerability.
Fix
Out of bounds Read
Integer Underflow
Integer Overflow
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Virtualbox
Red Os