PT-2024-4907 · Oracle+1 · Virtualbox+1

Zheyu Ma

·

Published

2024-04-16

·

Updated

2024-12-05

·

CVE-2024-21108

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Oracle VM VirtualBox versions prior to 7.0.16
Description: The issue is related to insufficient input validation in the Core component of Oracle VM VirtualBox, allowing a low-privileged attacker with logon access to the infrastructure to compromise Oracle VM VirtualBox. Successful attacks can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data.
Recommendations: To resolve the issue, update to version 7.0.16 or later. As a temporary workaround, consider restricting access to the Core component of Oracle VM VirtualBox to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-05431
CVE-2024-21108
MGASA-2024-0232

Affected Products

Virtualbox
Red Os