Oracle VirtualBox Unsupported Version Detection (Windows)

critical Nessus Plugin ID 92789

Synopsis

A virtualization application installed on the remote Windows host is no longer supported.

Description

According to its self-reported version number, the installation of Oracle VirtualBox on the remote Windows host is no longer supported.

Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it is likely to contain security vulnerabilities.

Solution

Upgrade to a version of Oracle VirtualBox that is currently supported.

See Also

http://www.nessus.org/u?925c7fb8

http://www.nessus.org/u?466fb425

https://www.virtualbox.org/wiki/Download_Old_Builds

Plugin Details

Severity: Critical

ID: 92789

File Name: virtualbox_unsupported_win.nasl

Version: 1.5

Type: local

Agent: windows

Family: Windows

Published: 8/8/2016

Updated: 2/16/2021

Supported Sensors: Nessus Agent, Nessus

Risk Information

CVSS Score Rationale: Tenable score for unsupported products

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: manual

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:oracle:vm_virtualbox

Required KB Items: installed_sw/Oracle VM VirtualBox

Reference Information

IAVA: 0001-A-0577