CVE-2024-37085

Confirmed PUBLISHED

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full...

VMware · VMware ESXi, VMware Cloud Foundation
Exploited in the wild Used in malware PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
6.8 Medium

At a Glance

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.

malware ransomware cisa nessus_scanner
CVE Published
Jun 25, 2024
Exploitation Reported
Jul 30, 2024
CVSS
6.8 Medium
EPSS
Remote Low complexity

Affected Versions

Vendor Product Version Status
vmware
esxi

7.0

Affected
vmware
cloud_foundation

5.0 to < 5.2

Affected
vmware
cloud_foundation

4.0 to < 5.0

Affected
vmware
esxi

8.0 to < ESXi80U3-24022510

Affected
n/a
VMware ESXi

8.0 to < ESXi80U3-24022510

Affected
n/a
VMware ESXi

7.0

Affected
n/a
VMware Cloud Foundation

5.x

Affected
n/a
VMware Cloud Foundation

4.x

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.