Impact
A flaw in the Core component of Oracle VM VirtualBox 7.2.16 allows an attacker who is already logged on with low privileges to trigger a repeating cause a hang or frequently repeatable crash of VirtualBox, as well as unauthorized update, insert or delete access to some of VirtualBox accessible data. The vulnerability presents integrity and availability impacts, reflected in a CVSS Base Score of 6.1. The weakness is CWE-400.
Affected Systems
Oracle VM VirtualBox 7.2.16 running on any host where the user has low privileges and can log on to the infrastructure where VirtualBox executes.
Risk and Exploitability
The CVSS score indicates moderate risk. The EPSS score of < 1% suggests a very low probability of exploitation at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog access, but any logged‑on user with low‑privileged access can exploit this flaw through arbitrary operations within the VirtualBox process.
OpenCVE Enrichment