Impact
The vulnerability resides in the core component of Oracle VirtualBox 7.2.16. A low‑privileged attacker who is already logged onto the Windows host can exploit this flaw without any user interaction, leading to the takeover of the VirtualBox instance. Attack success would destroy confidentiality, integrity, and availability of the VirtualBox data and processes.
Affected Systems
Oracle Corporation’s VirtualBox product, specifically version 7.2.16 running on Windows hosts, is impacted. The issue is not present in other versions or on non‑Windows platforms according to the available information.
Risk and Exploitability
The CVSS v3.1 score of 7.8 indicates serious impact when exploited, yet the EPSS score is below 1% and the flaw is not listed in the CISA KEV catalog, suggesting low current exploitation probability. Because the attack vector is local, low privilege, and requires no user interaction, users who own the affected Windows host face a moderate to high risk of full compromise if remediation is not applied.
OpenCVE Enrichment