Oracle · Virtualbox · CVE-2021-2409
**Name of the Vulnerable Software and Affected Versions**
Oracle VM VirtualBox versions prior to 6.1.24
**Description**
The issue is related to insufficient input validation in the Core component of Oracle VM VirtualBox, allowing a high-privileged attacker with logon to the infrastructure to compromise Oracle VM VirtualBox. Successful attacks can result in the takeover of Oracle VM VirtualBox and may significantly impact additional products.
**Recommendations**
For versions prior to 6.1.24, update to version 6.1.24 or later to resolve the issue. As a temporary workaround, consider restricting access to the Core component of Oracle VM VirtualBox to minimize the risk of exploitation.