Impact
The flaw in Oracle VM VirtualBox 7.2.14 permits an attacker who has local high‑privileged access to the host to trigger a hang or repeated crash of the VirtualBox process, resulting in a complete denial of service of the virtualization platform. The vulnerability does not provide a path to arbitrary code execution or compromise confidentiality, but the availability impact can disrupt any services that rely on the host to run virtual machines.
Affected Systems
Oracle Corporation’s VirtualBox version 7.2.14 is affected. Because the CVSS vector indicates a scope change (S:C), the impact may extend to other software running on the same host, potentially affecting applications that depend on the virtualization layer.
Risk and Exploitability
The CVSS v3.1 score of 6.0 reflects a local attack with low complexity and high availability impact. The EPSS score of < 1% indicates an extremely low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Based on the CVE vector, the likely attack vector is local access; the CVSS score and the description confirm that a high‑privileged attacker can induce a crash by interacting with VirtualBox. The scope change suggests that a successful exploit could impact additional products on the host, though no remote reachability is described.
OpenCVE Enrichment