Impact
A vulnerability in the VMSVGA device of Oracle VM VirtualBox 7.2.8 allows a high‑privileged attacker who has logged on to the host system to force the VirtualBox application to hang or crash repeatedly. The flaw results in a complete denial of service of the virtual machine platform, impacting availability but not confidentiality or integrity of data stored by VirtualBox. The weakness is a local, high‑privilege denial‑of‑service flaw identified through improper handling of VMSVGA requests.
Affected Systems
Oracle Corporation’s VirtualBox virtualization product, version 7.2.8, on any host platform supported by the product is affected. The issue is specific to the VMSVGA device implementation in that release.
Risk and Exploitability
The CVSS v3.1 base score is 6.0, indicating a medium‑severity vulnerability that solely impacts availability. The EPSS score is below 1 %, implying a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local high‑privilege access to the host; an attacker with such access can trigger the crash, but the lack of network exposure and the low EPSS score reduce the urgency of widespread exploitation. Nonetheless, any system running VirtualBox 7.2.8 that could be reached by a privileged user should be considered at risk of a local availability attack.
OpenCVE Enrichment