Impact
The vulnerability in Oracle VM VirtualBox 7.2.14 allows a high‑privileged attacker who has logged on to the host machine to manipulate VirtualBox internals, causing a hang or repeatedly crashing the application, and to perform unauthorized update, insert or delete operations, as well as read access to some of the data exposed by VirtualBox. This flaw is a local privilege escalation problem that can also lead to confidentiality and integrity impacts because the attacker may access or alter VirtualBox‑managed data. The weakness falls under improper access control and information exposure, consistent with recognized CWEs for unauthorized data modification and disclosure.
Affected Systems
Oracle Corporation’s Oracle VM VirtualBox version 7.2.14 is the only affected release noted in the publicly available information. No other version or build is listed as vulnerable in the CVE data.
Risk and Exploitability
The CVSS 3.1 base score of 7.3 indicates a high‑severity vulnerability that is exploitable from the local environment (attack vector Local, Privileges High, User Interaction None). Because the EPSS score is reported as < 1% and the vulnerability is not listed in the CISA KEV catalog, the current exploit probability is very low yet non‑zero, but the risk remains significant for systems running the affected VirtualBox instance, especially if unrestricted local accounts exist and the host is not well isolated. Successful exploitation would allow a user with local access to cause a denial of service and potentially access or modify confidential data stored by VirtualBox.
OpenCVE Enrichment