Oracle · Virtualbox · CVE-2024-21106
Name of the Vulnerable Software and Affected Versions:
Oracle VM VirtualBox versions prior to 7.0.16
Description:
The issue is related to insufficient input validation in the Core component of Oracle VM VirtualBox, allowing a low-privileged attacker with logon access to the infrastructure to compromise Oracle VM VirtualBox. Successful attacks can result in unauthorized ability to cause a hang or frequently repeatable crash of Oracle VM VirtualBox, potentially impacting additional products.
Recommendations:
Update to version 7.0.16 or later to resolve the issue.
As a temporary workaround, consider restricting access to the Core component of Oracle VM VirtualBox to minimize the risk of exploitation.