Impact
The Oracle VM VirtualBox 7.2.12 release contains a flaw in its Core component that permits a low‑privileged user who has logged onto the host system to trigger a crash or hang of the VirtualBox application. The vulnerability does not provide a path to code execution or privilege escalation; instead, successful exploitation results in a loss of availability for anyone relying on the VM host. The CVSS score of 5.5 reflects the significant impact on availability while indicating that confidentiality and integrity are unaffected.
Affected Systems
The affected product is Oracle Corporation’s Oracle VM VirtualBox version 7.2.12. No other major or minor releases of VirtualBox have been identified as impacted by this vulnerability. Administrators should verify that any deployed VirtualBox hosts are running this exact version and consider upgrading if possible.
Risk and Exploitability
The EPSS score of less than 1% suggests a low likelihood that attackers are attempting to exploit this issue in the wild. The vulnerability is not listed in the CISA KEV catalog, reinforcing its limited exploitation profile. Nevertheless, the availability impact can disrupt business operations if VirtualBox hosts are critical. The attack vector is inferred to be local: an attacker who can log onto the host system and execute code can push the vulnerable component through a trigger that causes a crash or hang. Patching the vulnerability removes the trigger and eliminates the risk of disruption.
OpenCVE Enrichment