Impact
A vulnerability in the core component of Oracle VM VirtualBox enables an unauthenticated attacker who can reach the host via Remote Desktop Protocol to force the guest management interface to hang or repeatedly crash, resulting in an availability interruption. The flaw is a classic resource‑exhaustion weakness (CWE‑400) that can be triggered without user interaction and does not affect confidentiality or integrity.
Affected Systems
Oracle Corporation’s VirtualBox Virtualization product, version 7.2.16, is the only version identified as affected. No other releases are listed in the advisory, so systems running earlier or later releases are not known to be vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑severity availability impact. The EPSS figure of less than 1% suggests that, while exploitation is possible, it is not frequently observed. The vulnerability is not currently listed in the CISA KEV catalog, meaning no confirmed widespread exploit activity has been reported. The likely attack path involves an unauthenticated RDP connection to the VirtualBox host; the attacker does not need special privileges or authentication, making the exploitation straightforward once the host is reachable over the network.
OpenCVE Enrichment