Impact
The vulnerability resides in the core component of Oracle VM VirtualBox 7.2.14 and permits a local user who has high‑privilege access to provoke a crash or hang of the Hypervisor. When exploited, the flaw results in a complete loss of availability for the VM environment, effectively denying any operations performed by virtual machines on the host. No path for remote code execution, privilege expansion beyond the existing high‑privilege credentials, or data exfiltration is described in the source material. The weakness corresponds to CWE‑770, indicating a failure to enforce a resource limit and allowing a resource exhaustion or denial of service condition.
Affected Systems
Oracle VM VirtualBox version 7.2.14 is the only documented affected release in the CVE entry. No other product variants or newer versions are mentioned as impacted.
Risk and Exploitability
The CVSS 3.1 base score of 4.4 reflects a low‑to‑moderate risk for a local attacker with high privileges and low attack complexity. The EPSS score of less than 1% suggests that exploitation is unlikely in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local access to a host running VirtualBox; once present, the attacker can trigger the crash without further interaction, but cannot acquire additional privileges or access sensitive data.
OpenCVE Enrichment