Is VirtualBox 5.0.40 patched?
Current stable (7.2.10): 100/100
5.0.40 has 127 open critical-or-high vulnerabilities. Run 7.0.24 or later to clear them. See what 7.0.24 fixes →
Summary iPlain-English security status for VirtualBox 5.0.40, built from its CVEs, active-exploitation data, end-of-life date and latest release.
VirtualBox 5.0.40 is part of the 5.0 release line. 1 actively-exploited vulnerability affects it (CISA KEV). 1 is linked to ransomware campaigns (CISA KEV). The minimum safe version is 7.0.24 — upgrade to it or later to clear the open critical/high issues. The 5.0 line reached end-of-life on 2017-05-31, so it no longer receives security patches. The latest supported VirtualBox release is 7.2.10.
Known issues affecting 5.0.40
Exploited first, then by exploitation probability.
CVE-2019-2725 CRITICAL exploited ransomware EPSS 100% → fixed in 6.1.2 CVE-2015-0235 HIGH EPSS 95% → fixed in 5.1.24 CVE-2017-5715 MEDIUM EPSS 74% → fixed in 5.2.6 CVE-2018-0735 MEDIUM EPSS 5% → fixed in 6.0.0 CVE-2019-2511 HIGH EPSS 4% → fixed in 5.2.24 CVE-2018-5407 MEDIUM EPSS 3% → fixed in 6.0.0 CVE-2021-2279 HIGH EPSS 3% → fixed in 6.1.20 CVE-2020-2959 HIGH EPSS 3% → fixed in 6.1.6 CVE-2016-5605 CRITICAL EPSS 2% → see advisory CVE-2018-3294 CRITICAL EPSS 2% → fixed in 5.2.20 CVE-2019-2721 HIGH EPSS 2% → fixed in 6.0.6 CVE-2019-10219 MEDIUM EPSS 2% → fixed in 6.1.32 CVE-2018-3295 HIGH EPSS 2% → fixed in 5.2.20 CVE-2017-10129 HIGH EPSS 2% → see advisory CVE-2022-39425 HIGH EPSS 2% → fixed in 6.1.40 CVE-2017-10204 HIGH EPSS 2% → see advisory CVE-2024-21111 HIGH EPSS 2% → fixed in 7.0.16 CVE-2022-39424 HIGH EPSS 1% → fixed in 6.1.40 CVE-2023-21886 HIGH EPSS 1% → fixed in 7.0.6 CVE-2022-39426 HIGH EPSS 1% → fixed in 6.1.40Other VirtualBox versions
Check another release line of VirtualBox.
Frequently asked
Is VirtualBox 5.0.40 patched?
No — 1 actively-exploited vulnerability affects VirtualBox 5.0.40. Upgrade to at least 7.0.24.
What version should I upgrade VirtualBox 5.0.40 to?
Upgrade VirtualBox 5.0.40 to at least 7.0.24 to clear its 127 open critical-or-high vulnerabilities.
When does VirtualBox 5.0 reach end-of-life?
VirtualBox 5.0 reached end-of-life on 2017-05-31 and no longer receives security patches.
What is the latest version of VirtualBox?
The latest supported VirtualBox release is 7.2.10.
Is VirtualBox 5.0.40 still receiving security updates?
No — VirtualBox 5.0.40 is on the 5.0 line, which reached end-of-life on 2017-05-31 and no longer receives security updates. Upgrade to 7.2.10 or later to stay supported.
Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against Oracle's official advisory before you patch or upgrade — VirtualBox official site ↗