Impact
The vulnerability enables a low‑privileged user with logged‑on access to the host running Oracle VM VirtualBox to initiate a crash of the virtualization engine. Once the fault is triggered through a user‑action, the VirtualBox process repeatedly hangs or exits, effectively denying service to all virtual machines and host applications that depend on it. This is a classic resource exhaustion flaw (CWE‑400).
Affected Systems
Oracle VirtualBox version 7.2.16 is affected. No other product versions were listed as vulnerable.
Risk and Exploitability
The CVSS score of 4.4 indicates a medium severity with a significant Availability impact. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild at the time of analysis. Attacks require low‑privileged local access and a human‑initiated action; the flaw can be used to disrupt the VirtualBox host service, which may impact many dependent virtual machines.
OpenCVE Enrichment