Impact
A privileged local attacker with high privileged access on a host running Oracle VM VirtualBox can exploit a flaw in the Core component to force the VirtualBox process to hang or crash. This vulnerability, classified as CWE-400, is easily exploitable and results in a complete denial of service by disrupting the availability of the VirtualBox service.
Affected Systems
The flaw affects Oracle VM VirtualBox version 7.2.16. No other specific product versions are listed, but the CVE notes that a scope change may impact additional related products.
Risk and Exploitability
The CVSS score of 6.0 reflects a moderate severity of the availability impact. The EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Because the attacker requires high privileged local access and the vector is local, the exploitation likelihood depends on the security of the deployment environment rather than on network exposure.
OpenCVE Enrichment