CNNVD-202510-2639 Information
CNNVD ID
CNNVD-202510-2639
Related CVE
- CNNVD Published: 2025-10-21
Description (Chinese)
Oracle Virtualization是美国甲骨文(Oracle)公司的一套虚拟化解决方案。该产品用于统一管理从应用程序到磁盘的整个硬件和软件体系,可实现从桌面到数据中心的虚拟化。 Oracle Virtualization的Oracle VM VirtualBox 7.1.12版本和7.2.2版本存在安全漏洞,该漏洞源于高权限攻击者可利用登录基础设施执行攻击,可能导致未经授权访问关键数据或完全访问所有Oracle VM VirtualBox可访问数据。
Description (English)
Oracle Virtualization is a virtual solution for Oracle. The product is used for the integrated management of the entire hardware and software system from the application to the disk, with virtualization from the desktop to the data centre. There is a security loophole in Oracle VM VirtualBox, version 7.1.12 and version 7.2.2, which stems from the fact that high-authority attackers can use the log-in infrastructure to carry out attacks, which may result in unauthorized access to key data or full access to all Oracle VM VirtualBox data.
Hazard Level
High
Vulnerability Type
其他
Affected Vendor
甲骨文
Published
2025-10-21
Last Modified
2026-02-24
References
https://www.oracle.com/security-alerts/cpuoct2025.html https://vigilance.fr/vulnerability/Oracle-VM-VirtualBox-vulnerabilities-of-October-2025-48548 https://access.redhat.com/security/cve/cve-2025-62592
Patch
https://www.oracle.com/security-alerts/cpuoct2025.html
Share on: