QID 375481

Date Published: 2021-04-21

QID 375481: Oracle VM VirtualBox Multiple Vulnerabilities(CPUAPR2021)

Oracle VM VirtualBox is an x86 virtualization software package.

Affected Versions:-
Oracle VM VirtualBox prior to 6.1.20

QID Detection Logic (Authenticated):
This QID checks the vulnerable version of Oracle VM VirtualBox by checking the file version of file "VirtualBox.exe".

Successful attacks of this vulnerability could allow an authenticated malicious user to obtain sensitive information resulting in a high confidentiality impact using unknown attack vectors.

  • CVSS V3 rated as Critical - 8.2 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Refer to vendor advisory Oracle VM VirtualBox APR2021
    Software Advisories
    Advisory ID Software Component Link
    CPUAPR2021 URL Logo www.oracle.com/security-alerts/cpuapr2021.html#AppendixOVIR