Oracle · Virtualbox · CVE-2023-21990
**Name of the Vulnerable Software and Affected Versions**
Oracle VM VirtualBox versions prior to 6.1.44
Oracle VM VirtualBox versions prior to 7.0.8
**Description**
The issue is related to a use-after-free vulnerability in the Core component of Oracle VM VirtualBox, allowing a high-privileged attacker with logon to the infrastructure to compromise Oracle VM VirtualBox. Successful attacks can result in the takeover of Oracle VM VirtualBox. The vulnerability may also impact additional products.
**Recommendations**
For versions prior to 6.1.44, update to version 6.1.44 or later.
For versions prior to 7.0.8, update to version 7.0.8 or later.
As a temporary workaround, consider restricting access to the Core component of Oracle VM VirtualBox until a patch is available.