Impact
A vulnerability in the core component of Oracle VM VirtualBox 7.2.16 allows a high‑privileged attacker who can log on to the host infrastructure to force the virtualization software to crash or hang repeatedly, effectively denying availability. The impact is limited to the VirtualBox instance but the scope change indicates that other dependent products could also be adversely affected by this failure. The weakness is a denial‑of‑service condition rather than a data breach or credential compromise.
Affected Systems
Affected systems are Oracle VirtualBox version 7.2.16. No other versions are listed as impacted; however, any installation of this exact product should be considered vulnerable until an update is applied.
Risk and Exploitability
The base CVSS score of 6.0 indicates a moderate severity, with local access (AV:L) and high privilege (PR:H) required for exploitation. The EPSS score of < 1% suggests that the likelihood of this vulnerability being actively exploited at this time is very low, and it is not listed in CISA’s KEV catalog. Nevertheless, because a successful exploit causes a complete denial of service, administrators should treat the risk as significant for environments where VirtualBox hosts are critical to operations. The attack vector is local and requires high privileges, so it is most relevant when an attacker has physical or administrative access to the host machine.
OpenCVE Enrichment