PT-2024-4906 · Oracle+1 · Virtualbox+1

Reima Ishii

·

Published

2024-04-16

·

Updated

2024-12-05

·

CVE-2024-21106

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Oracle VM VirtualBox versions prior to 7.0.16
Description: The issue is related to insufficient input validation in the Core component of Oracle VM VirtualBox, allowing a low-privileged attacker with logon access to the infrastructure to compromise Oracle VM VirtualBox. Successful attacks can result in unauthorized ability to cause a hang or frequently repeatable crash of Oracle VM VirtualBox, potentially impacting additional products.
Recommendations: Update to version 7.0.16 or later to resolve the issue. As a temporary workaround, consider restricting access to the Core component of Oracle VM VirtualBox to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-05430
CVE-2024-21106
MGASA-2024-0232

Affected Products

Virtualbox
Red Os