LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-37085: VMware ESXi Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 30, 2024
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Aug 20, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-37085 to its Known Exploited Vulnerabilities catalog on Jul 30, 2024, with a federal patch deadline of Aug 20, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to…

CVE-2024-37085 is an authentication bypass vulnerability in VMware ESXi. When an ESXi host is configured to use Active Directory for user management, a malicious actor who already holds sufficient AD permissions can regain full administrative access to that host by re-creating a previously deleted AD group (the default name is “ESXi Admins”).

Because the flaw allows complete host takeover and is known to be used by ransomware operators, organizations running AD-integrated ESXi hosts should treat it as a high-priority risk and confirm their exposure and remediation status against the vendor advisory.

How it works

The vulnerability is classified as CWE-305 (authentication bypass). ESXi can be joined to Active Directory so that membership in a designated AD group grants administrative rights on the hypervisor. If that group is later deleted from AD, the host continues to trust the group name. An attacker who can create groups in the same AD domain simply re-creates a group with the exact configured name. Once the group exists again, any account the attacker places in it is treated by ESXi as a full administrator, bypassing the intended authentication and authorization controls.

No remote unauthenticated exploit is required; the attacker must already possess enough AD privileges to create or restore the group. The result, however, is unrestricted access to the ESXi host and therefore to every virtual machine it runs.

Am I affected? How to find it in your systems

VMware ESXi is commonly deployed as the bare-metal hypervisor in private clouds, virtual desktop infrastructure, and enterprise server farms. Any host that has been configured for Active Directory authentication is potentially in scope.

Exact affected versions and configuration details must be confirmed against the vendor advisory; do not rely solely on the presence or absence of a particular build number.

How to remediate

Apply the vendor-supplied update or mitigation for CVE-2024-37085 as soon as it can be tested and staged. Follow the CISA-required action: implement the mitigations described in the vendor instructions, or discontinue use of the product if no mitigations are available.

If you can't patch immediately

Until the vendor update can be applied, reduce risk with compensating controls:

If your data may have been exposed

Actively exploited authentication-bypass vulnerabilities on hypervisors frequently lead to ransomware deployment and data theft. If you discover evidence of unauthorized ESXi access, treat the incident as a potential breach: isolate affected hosts, preserve forensic images, and begin containment and recovery according to your incident-response plan. You can also run a free exposure scan of your email address to check whether associated credentials or personal data already appear in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedVMware · ESXi
WeaknessCWE-305
Added to CISA KEVJul 30, 2024
Federal patch deadlineAug 20, 2024
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities