Impact
The flaw resides in the core component of Oracle VM VirtualBox 7.2.16 and can be exploited by an attacker who has logged onto the host system. This local attack, which requires high privileges, permits the attacker to read a subset of data available to VirtualBox and to trigger a partial denial of service that causes the hypervisor to become unresponsive or restart. While the vulnerability is confined to VirtualBox, the scope change noted in the description implies that additional products interacting with the hypervisor could also be affected.
Affected Systems
Oracle Corporation’s VirtualBox version 7.2.16 is affected; other versions are not listed as vulnerable.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation in current environments. The vector indicates a local attack requiring high privileges. Successful exploitation leads to unauthorized data reading and a partial service outage for VirtualBox, with the potential to impact other products that rely on the hypervisor due to the scope change.
OpenCVE Enrichment