Impact
The flaw is an uncontrolled resource consumption issue (CWE‑400) in the Oracle VM VirtualBox core component in version 7.2.12. An attacker who can log on with high‑privileged rights on the host can trigger the defect, causing the VirtualBox engine to hang or crash. The resulting unavailability constitutes a denial of service to any virtual machines managed by that host. No direct compromise of confidentiality or integrity is implied by the description.
Affected Systems
Oracle VM VirtualBox version 7.2.12 is affected. No other versions are listed. The vendor product is Oracle Corporation: Oracle VM VirtualBox.
Risk and Exploitability
The CVSS v3.1 base score of 6.0 reflects moderate severity with local access and high privilege required. The EPSS score of < 1% indicates a very low likelihood of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local with an attacker who already has administrative or similar high‑privileged rights on the host system. Exploitation would involve triggering the defect that causes the VirtualBox engine to crash or become unresponsive, resulting in a denial‑of‑service condition. Based on the description, it is inferred that the crash could interrupt active virtual machine operations, but this cannot be confirmed without further vendor details.
OpenCVE Enrichment