Impact
VirtualBox 7.2.16 allows a low‑privilege user to compromise the VirtualBox instance. The exploit requires a human interaction from another person and is of high complexity, but if successful it can lead to complete takeover of Oracle VM VirtualBox, thereby affecting confidentiality, integrity and availability as indicated by a CVSS 3.1 Base Score of 7.5.
Affected Systems
Oracle Corporation’s Oracle VM VirtualBox version 7.2.16 is affected.
Risk and Exploitability
The CVSS score of 7.5 reflects a high severity local attack with a scope change. The EPSS score is below 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, the requirement for human interaction and the potential for full compromise suggests that environments hosting VirtualBox should treat this as a moderate to high risk until a fix is applied.
OpenCVE Enrichment