Impact
The vulnerability resides in the Core component of Oracle VM VirtualBox 7.2.14. It represents a CWE-284 (Access Control) flaw, allowing a local user with high privileges to cause a hang or repeatable crash, effectively denying availability. In addition, the attacker can update, insert, or delete data accessible to VirtualBox and read a subset of that data, compromising confidentiality and integrity.
Affected Systems
Affected systems are installations of Oracle VM VirtualBox version 7.2.14. Based on the description, it is inferred that the vulnerability may also affect other Oracle virtualization products because the flaw resides in the core component that is shared across multiple product lines. Any system running Oracle VM VirtualBox 7.2.14 is therefore at risk.
Risk and Exploitability
The CVSS base score of 7.3 indicates high severity. The attack requires a logged‑on local account with high privileges, as shown by the CVSS vector AV:L. It is inferred that remote exploitation is not publicly disclosed. The EPSS score of < 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known active exploitation. Nevertheless, the impact of a successful attack includes complete denial of service and unauthorized modification or disclosure of VirtualBox data, which could lead to further system compromise if the virtual machines are used for critical workloads.
OpenCVE Enrichment