Impact
The vulnerability in Oracle VM VirtualBox 7.2.14 results from an improper authorization check that allows a high‑privileged attacker logged onto the host to cause the VirtualBox process to hang or crash. Because the CVSS vector indicates a changed scope (S:C), the flaw can affect additional components beyond VirtualBox, potentially impacting the host operating system or other services running in the same environment. This leads to a complete denial of service for virtual machine operations and management.
Affected Systems
Oracle Corporation's VirtualBox product, specifically version 7.2.14, is impacted. Systems running this version on host infrastructure are at risk. Any environment that relies on VirtualBox for running virtual machines should verify their appliance version.
Risk and Exploitability
The CVSS 3.1 Base Score of 6.0 shows a moderate severity, with a local attack (AV:L), low complexity (AC:L), high privilege requirement (PR:H), and a changed scope. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Due to the scope change, an attacker can cause a denial of service that may extend to other components on the host, but the vulnerability does not enable remote code execution or data exfiltration. The risk remains moderate and warrants timely remediation.
OpenCVE Enrichment