Impact
Oracle VM VirtualBox version 7.2.16 contains a flaw that allows a local user with high privileges, who can rely on another person’s interaction on the same host, to force the hypervisor to crash. The vulnerability is a local capability escalation issue classified as CWE-284 and results in a complete denial of service for the VirtualBox service without granting additional privileges or affecting other system components.
Affected Systems
The product affected is Oracle VM VirtualBox version 7.2.16, supplied by Oracle Corporation. No other versions or products are listed as impacted.
Risk and Exploitability
The CVSS base score of 4.2 (AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H) indicates a low availability impact. The EPSS score is less than 1%, suggesting a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attacks require a local high‑privilege user and a human interaction from another individual, limiting the risk to environments where privileged users can influence other users on the same host. There is no known remote exploitation path or extra attack surface beyond the localized crash scenario.
OpenCVE Enrichment