Impact
The vulnerability is a Resource Exhaustion flaw (CWE-400) that allows a low‑privileged attacker who can reach the VirtualBox host via Remote Desktop Protocol to cause the VirtualBox service to hang or crash repeatedly, resulting in a complete denial of service. The impact affects availability only, with no compromise of confidentiality or integrity reported.
Affected Systems
Oracle VM VirtualBox 7.2.16 on any host that exposes Remote Desktop Protocol access. Only the VirtualBox service is affected; other host services remain operational.
Risk and Exploitability
The CVSS Base Score of 5.3 indicates moderate risk. EPSS is below 1%, suggesting that exploitation with publicly available tools is unlikely at present. The vulnerability is not listed in CISA KEV. The exploit vector requires network access via RDP and a low privilege user on the target host, making it less likely to be leveraged by highly skilled adversaries but still a concern for environments where RDP is broadly exposed.
OpenCVE Enrichment