ZeroHour

CVE-2026-87270

large

Local Privilege Escalation in Oracle VM VirtualBox 7.2.16 (Windows Hosts)

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87270 is a local privilege escalation vulnerability in the Core component of Oracle VM VirtualBox, affecting supported version 7.2.16 on Windows hosts only. It is easily exploitable by a low-privileged attacker who already has a logon on the machine where VirtualBox executes, requiring no user interaction. Successful exploitation allows the attacker to compromise and take over Oracle VM VirtualBox, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8). In practice, this means any standard user account on a Windows host running the vulnerable version could pivot into full control of the hypervisor and its virtual machines. No public proof-of-concept exists and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation in the wild is not currently observed.

What to do: Upgrade VirtualBox on Windows hosts from 7.2.16 to the latest release provided in Oracle's Critical Patch Update. Because exploitation requires only a low-privileged local account, minimize and audit local user accounts on machines that run VirtualBox, and check Windows hosts for unexpected VirtualBox process or driver activity.

Affected
Oracle VM VirtualBox
Estimated exposure
largelikely hundreds of thousands to low millions of Windows hosts, with only the subset running the 7.2.16 point release actually affected — VirtualBox is one of the most widely installed free desktop hypervisors (tens of millions of cumulative downloads), but installs are developer/desktop machines rather than internet-exposed servers, and only a single supported point release…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability applies to Windows host only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.