Impact
The vulnerability exists in the core component of Oracle VM VirtualBox 7.2.14 and allows a local attacker with high privileges to trigger a crash or hang of the hypervisor. Successful exploitation causes a complete denial of service that disrupts all virtual machines running on the host. The flaw does not provide a path to remote code execution, privilege escalation beyond the attacker’s existing credentials, or data exfiltration.
Affected Systems
Oracle VM VirtualBox 7.2.14 is the only documented affected release; no other product variants or newer versions are mentioned as impacted.
Risk and Exploitability
The CVSS 3.1 base score of 4.4 indicates a low‑to‑moderate risk with local access and low attack complexity. The EPSS score of less than 1% signals that exploitation is unlikely, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local high‑privilege login; once achieved, the attacker can trigger the crash without further interaction, but cannot gain additional privileges or data access.
OpenCVE Enrichment