CNNVD-202510-2641 Information

CNNVD ID

CNNVD-202510-2641

CVE-2025-61760

  • CNNVD Published: 2025-10-21

Description (Chinese)

Oracle Virtualization是美国甲骨文(Oracle)公司的一套虚拟化解决方案。该产品用于统一管理从应用程序到磁盘的整个硬件和软件体系,可实现从桌面到数据中心的虚拟化。VM VirtualBox是其中的一个虚拟机组件。 Oracle Virtualization的Oracle VM VirtualBox 7.1.12版本和7.2.2版本存在安全漏洞,该漏洞源于低权限攻击者可通过登录基础设施进行攻击,可能导致Oracle VM VirtualBox被接管。

Description (English)

Oracle Virtualization is a virtual solution for Oracle. The product is used for the integrated management of the entire hardware and software system from the application to the disk, with virtualization from the desktop to the data centre. VM VirtualBox is one of the virtual machine components. Oracle VM Virtual Box 7.1.12 and 7.2.2 of Oracle Virtualize have security loopholes, which stem from the fact that low-authority attackers can attack through access to infrastructure, which could lead to Oracle VM Virtual Box being taken over.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

甲骨文

Published

2025-10-21

Last Modified

2026-02-24

References

https://access.redhat.com/security/cve/cve-2025-61760 https://www.oracle.com/security-alerts/cpuoct2025.html https://vigilance.fr/vulnerability/Oracle-VM-VirtualBox-vulnerabilities-of-October-2025-48548

Patch

https://www.oracle.com/security-alerts/cpuoct2025.html

Share on: