Impact
The flaw resides in the Core component of Oracle VM VirtualBox and can be triggered by a local user with high privileges, causing the hypervisor to hang or crash, which results in a complete denial of service that affects the availability of virtual machines and any applications running inside them. The bug is a classic denial‑of‑service condition arising from improper resource management (CWE‑400). The potential impact is limited to availability; confidentiality and integrity are not affected.
Affected Systems
Oracle VM VirtualBox version 7.2.16 is listed as the affected release by the vendor; no other versions are explicitly marked as vulnerable in this CVE.
Risk and Exploitability
The CVSS base score of 6.0 indicates a moderate security impact focusing on availability, and the vector description (AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H) shows that the vulnerability requires local, authenticated access with high privileges. Based on the description, it is inferred that the attack vector is local. The EPSS score of less than 1% suggests that the problem is unlikely to be widely exploited at present, and the vulnerability is not in CISA’s KEV catalog. However, if a host is already compromised or an administrator account is abused, the flaw can be exercised with minimal effort, making the risk high for locally privileged systems.
OpenCVE Enrichment