Heap-Based Buffer Overflow in Oracle VM VirtualBox VMSVGA Enables Local Privilege Escalation
AI analysis
CVE-2026-71116 is a vulnerability in the Core component of Oracle VM VirtualBox, which ZDI describes as a heap-based buffer overflow in the VMSVGA virtual graphics component that can be leveraged for local privilege escalation. It is difficult to exploit and requires a highly privileged attacker with logon to the infrastructure where VirtualBox executes, with no user interaction required. Successful attacks result in takeover of Oracle VM VirtualBox, and because the vulnerability has scope change, impact may extend to additional products beyond VirtualBox itself. Users running Oracle VM VirtualBox 7.2.14 are affected. There is currently no evidence of exploitation: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.1% probability of exploitation in the next 30 days.
What to do: Upgrade Oracle VM VirtualBox to the patched release provided in Oracle's Critical Patch Update for this CVE (the specific fixed version is not stated in the available data; verify via Oracle's advisory). Check installed versions with the VirtualBox About dialog or 'VBoxManage --version' and restrict high-privileged local accounts on systems running VirtualBox until patched. Given the low exploitation likelihood, no emergency action is required beyond routine patching.
Affected
| Oracle VM VirtualBox (Core) | 7.2.14 (the supported version listed as affected by Oracle) |
Estimated exposure
massmillions of installations (VirtualBox has tens of millions of downloads; the share running the affected 7.2.14 release is unknown) — Oracle VM VirtualBox is one of the most widely deployed desktop/developer hypervisors, with tens of millions of downloads, and 7.2.14 was a current supported release at disclosure, but Oracle publishes no install counts and VirtualBox…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).