What do you mean - a secure sandbox? If you make a Windows configuration error and your virtual server gets cracked, it is not easy to crack Qemu, too, and so host system will probably (there is nothing you can be absolutely sure in when you deal with malicious third parties) be unharmed. But you virtual Windows server will be under attacker's control at least until you redeploy original VM image (and probably afterward, too, if you do not fix the problem).
|