Impact
The vulnerability exists in Oracle VM VirtualBox 7.2.14’s Core component and permits an unauthenticated local attacker—anyone able to log into the host—to cause the application to hang or repeatedly crash, producing a denial of service. In addition, the flaw allows the attacker to update, insert, or delete certain VirtualBox-accessible data, thereby compromising data integrity. The weakness was classified under CVSS v3.1 with a base score of 6.1 and affects integrity (low) and availability (high).
Affected Systems
The affected product is Oracle VM VirtualBox version 7.2.14, distributed by Oracle Corporation. No other Oracle VirtualBox releases are listed as vulnerable.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, and the EPSS score of less than 1 % suggests low likelihood of active exploitation. The vulnerability is not listed in CISA’s KEV catalog. Because exploitation requires local host access and some user interaction beyond the attacker’s control, the risk to an environment with restricted physical or console access is limited; however, any systems with permissive local access should address the flaw promptly.
OpenCVE Enrichment