Impact
The vulnerability resides in the core component of Oracle VM VirtualBox 7.2.14 and is identified as CWE-284. It permits a local attacker who already has high host‑level privileges to trigger a crash or hang, effectively denying availability of the VirtualBox service. The flaw does not provide code execution, data disclosure, or unauthorized network access.
Affected Systems
Oracle Corporation’s Oracle VM VirtualBox product, version 7.2.14. The defect may also impact other products that depend on VirtualBox, as attacks can significantly affect additional products.
Risk and Exploitability
The CVSS 3.1 vector indicates a local attack with low effort and high privilege (AV:L/AC:L/PR:H). Because the attacker must already possess privileged access to the host, the likelihood of exploitation depends on internal security controls. The EPSS score of <1% and the fact that this issue is not listed in CISA’s KEV catalog suggest that widespread exploitation has not yet been observed. Still, a successful attack results in a complete denial of service for environments that rely on continuous operation of VirtualBox and potentially for any other products that depend on it.
OpenCVE Enrichment