Impact
The vulnerability resides in the Core component of Oracle VM VirtualBox version 7.2.14. An unauthenticated attacker who can reach the VirtualBox service over Remote Desktop Protocol can trigger a hang or complete crash, causing a repeatable denial of service. The CVSS 3.1 base score of 7.5 reflects a high availability impact while confidentiality and integrity remain unaffected. This weakness is identified as CWE-284.
Affected Systems
The affected product is Oracle VM VirtualBox from Oracle Corporation, specifically version 7.2.14. Users running this version on any operating system that exposes the RDP interface are at risk.
Risk and Exploitability
The attack vector is network-based via RDP, requiring no authentication. The vulnerability is described as easily exploitable. Without a patch the risk is high; the CVSS score is 7.5 and EPSS is < 1%, and the flaw is not listed in CISA KEV. Because the flaw allows complete denial of service, it can disrupt virtualization workloads and potentially affect service availability in environments that rely on VirtualBox.
OpenCVE Enrichment