Is VirtualBox 4.2.38 patched?
Current stable (7.2.10): 100/100
4.2.38 has 123 open critical-or-high vulnerabilities. Run 7.0.24 or later to clear them. See what 7.0.24 fixes →
Summary iPlain-English security status for VirtualBox 4.2.38, built from its CVEs, active-exploitation data, end-of-life date and latest release.
VirtualBox 4.2.38 is part of the 4.2 release line. 1 actively-exploited vulnerability affects it (CISA KEV). 1 is linked to ransomware campaigns (CISA KEV). The minimum safe version is 7.0.24 — upgrade to it or later to clear the open critical/high issues. The 4.2 line reached end-of-life on 2015-12-31, so it no longer receives security patches. The latest supported VirtualBox release is 7.2.10.
Known issues affecting 4.2.38
Exploited first, then by exploitation probability.
CVE-2019-2725 CRITICAL exploited ransomware EPSS 100% → fixed in 6.1.2 CVE-2015-0235 HIGH EPSS 95% → fixed in 5.1.24 CVE-2017-5715 MEDIUM EPSS 74% → fixed in 5.2.6 CVE-2015-3195 MEDIUM EPSS 39% → fixed in 5.0.14 CVE-2014-2477 LOW EPSS 7% → see advisory CVE-2018-0735 MEDIUM EPSS 5% → fixed in 6.0.0 CVE-2019-2511 HIGH EPSS 4% → fixed in 5.2.24 CVE-2018-5407 MEDIUM EPSS 3% → fixed in 6.0.0 CVE-2016-0495 MEDIUM EPSS 3% → fixed in 5.0.14 CVE-2021-2279 HIGH EPSS 3% → fixed in 6.1.20 CVE-2016-3612 MEDIUM EPSS 3% → see advisory CVE-2020-2959 HIGH EPSS 3% → fixed in 6.1.6 CVE-2016-5605 CRITICAL EPSS 2% → see advisory CVE-2018-3294 CRITICAL EPSS 2% → fixed in 5.2.20 CVE-2019-2721 HIGH EPSS 2% → fixed in 6.0.6 CVE-2019-10219 MEDIUM EPSS 2% → fixed in 6.1.32 CVE-2018-3295 HIGH EPSS 2% → fixed in 5.2.20 CVE-2017-10129 HIGH EPSS 2% → see advisory CVE-2022-39425 HIGH EPSS 2% → fixed in 6.1.40 CVE-2017-10204 HIGH EPSS 2% → see advisoryOther VirtualBox versions
Check another release line of VirtualBox.
Frequently asked
Is VirtualBox 4.2.38 patched?
No — 1 actively-exploited vulnerability affects VirtualBox 4.2.38. Upgrade to at least 7.0.24.
What version should I upgrade VirtualBox 4.2.38 to?
Upgrade VirtualBox 4.2.38 to at least 7.0.24 to clear its 123 open critical-or-high vulnerabilities.
When does VirtualBox 4.2 reach end-of-life?
VirtualBox 4.2 reached end-of-life on 2015-12-31 and no longer receives security patches.
What is the latest version of VirtualBox?
The latest supported VirtualBox release is 7.2.10.
Is VirtualBox 4.2.38 still receiving security updates?
No — VirtualBox 4.2.38 is on the 4.2 line, which reached end-of-life on 2015-12-31 and no longer receives security updates. Upgrade to 7.2.10 or later to stay supported.
Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against Oracle's official advisory before you patch or upgrade — VirtualBox official site ↗