Impact
A flaw in Oracle VM VirtualBox 7.2.16 allows an unauthenticated local attacker who can log into the host system to compromise the VirtualBox process. The vulnerability can lead to unauthorized updates, inserts, or deletions of data accessed by VirtualBox and can cause the application to hang or repeatedly crash, representing a significant availability impact. The CVSS 3.1 vector indicates local attack with low complexity and no privileges, but user interaction is required, implying that the attacker must rely on another user to trigger the exploit.
Affected Systems
Oracle Corporation’s Oracle VM VirtualBox version 7.2.16 is the only product and version explicitly affected by this vulnerability.
Risk and Exploitability
The CVSS base score of 6.1 classifies this as a moderate severity flaw, while the EPSS score of less than 1% suggests a very low current exploitation probability. Because the exploit requires local access to a host where VirtualBox is installed, it is unlikely to be attacked remotely, but any compromised local account can be used to misconfigure VirtualBox or cause service interruptions. The vulnerability is not listed in the CISA KEV catalog, indicating no known large-scale exploitation yet.
OpenCVE Enrichment