In my company, the security team isn’t technical. They see CVE, find a vulnerable system, it gets flagged. We have to patch it.
We patched for a CVE last week that a malicious usb sound card device could be use the gain root.
On a Vm? Is that something we really need to worry about??