QID 375967

Date Published: 2021-10-20

QID 375967: Oracle Virtualized Manager (VM) VirtualBox Multiple Vulnerabilities For Windows (CPUOCT2021)

Oracle VM VirtualBox is an x86 virtualization software package.

Affected Versions:-
Oracle VM VirtualBox prior to 6.1.28

QID Detection Logic (Authenticated):
This QID checks the vulnerable version of Oracle VM VirtualBox by checking the file version of file "VirtualBox.exe".

Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox.

  • CVSS V3 rated as High - 6.7 severity.
  • CVSS V2 rated as Medium - 5.6 severity.
  • Solution
    Refer to vendor advisory Oracle VM VirtualBox OCT2021

    CVEs related to QID 375967

    Software Advisories
    Advisory ID Software Component Link
    cpuoct2021 URL Logo www.oracle.com/security-alerts/cpuoct2021.html#AppendixOVIR