Impact
The Oracle VM VirtualBox 7.2.12 core component contains an uncontrolled resource consumption flaw that allows a local user with low privileges to craft input that forces VirtualBox to consume excessive memory or CPU resources, ultimately causing it to hang or crash. This results in a complete denial of service on the host system, affecting any running virtual machines, while preserving confidentiality and integrity. The weakness is classified as CWE‑400.
Affected Systems
Only the 7.2.12 release of Oracle VM VirtualBox has been documented as vulnerable; other versions or editions are not listed as affected.
Risk and Exploitability
The CVSS 3.1 base score of 5.5 reflects moderate severity, and the vector components (AV:L/AC:L/PR:L/UI:N/S:U) reveal that the vulnerability requires local access with low privileges. The EPSS score of less than 1% indicates a low probability of widespread exploitation currently, and the vulnerability is not listed in the CISA KEV catalog. Because the attack vector is local, an adversary must already possess a user account on the host; no network attacker can trigger the flaw from outside.
OpenCVE Enrichment