Executive brief
A vulnerability in Oracle VM VirtualBox, a widely used virtualization platform, allows a privileged local user to cause the application to hang or crash completely. This denial-of-service attack can disrupt virtual machine operations and affect systems that depend on VirtualBox for infrastructure management, requiring administrator-level access to exploit.
Technical details
This is a denial-of-service vulnerability in the Core component of Oracle VM VirtualBox version 7.2.16. The vulnerability requires high privilege access (logon to the infrastructure) and local attack vector (AV:L). The root cause is in the Core component's handling of certain operations, which can be triggered without user interaction to cause a hang or repeated crash (complete DoS). Successful exploitation results in unavailability of the VirtualBox instance affecting the hypervisor and potentially guest systems, though no confidentiality or integrity is compromised. Patch availability is not specified in this advisory.
Affected products
- Oracle VM VirtualBox 7.2.16
Timeline
- 2026-09-15: disclosed