QID 375969
Date Published: 2021-10-20
QID 375969: Oracle Virtualized Manager (VM) VirtualBox Privilege Escalation Vulnerability (CPUOCT2021)
Oracle VM VirtualBox is an x86 virtualization software package.
Affected Versions:-
Oracle VM VirtualBox prior to 6.1.28
QID Detection Logic (Authenticated):
This QID checks the vulnerable version of Oracle VM VirtualBox by checking the file version of file "VirtualBox.exe".
Allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox.
Solution
Refer to vendor advisory Oracle VM VirtualBox OCT2021
Vendor References
CVEs related to QID 375969
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cpuoct2021 |
|