Impact
The vulnerability resides in the Core component of Oracle VM VirtualBox version 7.2.14. An attacker who already has high privileged access and can log on to the infrastructure can exploit the flaw to cause a hang or a repeatable crash. The CVSS 3.1 score of 6.0 reflects a high availability impact; confidentiality and integrity are not affected. The description indicates that successful exploitation results in a complete denial of service of VirtualBox, and because the scope of the vulnerability is marked as changed, other related products might also be affected.
Affected Systems
Oracle Corporation’s Oracle VM VirtualBox, version 7.2.14, is the only affected product identified. No other vendors or product versions are listed as impacted.
Risk and Exploitability
The CVSS score of 6.0 places this vulnerability in the medium severity range, but its local nature (low AV) combined with the need for high privileges (PR H) means an attacker must already be able to log in to the machine. Because the EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, there is no current evidence of widespread exploitation. The risk remains moderate, with the main threat being a potential denial of service to users running VirtualBox on the affected host.
OpenCVE Enrichment