Oracle VirtualBox
Oracle VirtualBox is continuously required updates because of security vulnerabilities and our Risk Management team has flagged this software as installed on a Windows Server platform as high risk software on the network stating that "Running this kind of solution allows a shadow environment to be run simultaneously that is unmanaged/unsecured." Has anyone had to mitigate the risk associated with running a virtual box on a Windows Server? Only thought I've had so far is to shut the server down when we are not installing upgrades or patches.