PT-2024-4541 · Vmware · Vmware Esxi

Danielle Kuznets Nohi

+2

·

Published

2024-06-25

·

Updated

2025-08-05

·

CVE-2024-37085

CVSS v2.0
8.3
VectorAV:N/AC:L/Au:M/C:C/I:C/A:C

**Name of the Vulnerable Software and Affected Versions:**

VMware ESXi versions 7.0 through 8.0

VMware Cloud Foundation (vSphere) versions LE5.2

**Description:**

VMware ESXi contains an authentication bypass vulnerability that allows malicious actors with sufficient Active Directory (AD) permissions to gain full access to an ESXi host previously configured to use AD for user management. This is achieved by recreating the configured AD group ('ESXi Admins' by default) after it has been deleted from AD. Multiple ransomware groups, including BlackByte, Akira, and Storm-0506, are actively exploiting this vulnerability. They are utilizing tools like Cobalt Strike, Pypykatz, and vulnerable drivers to steal credentials, move laterally within networks, and deploy ransomware such as Black Basta and Akira. Cisco Talos has observed the BlackByte ransomware group exploiting this vulnerability to control virtual machines. Scattered Spider hackers are also leveraging this flaw in conjunction with social engineering and custom rootkits.

**Recommendations:**

VMware ESXi versions 7.0 through 8.0: Apply the latest security updates provided by VMware to address this authentication bypass vulnerability.

VMware Cloud Foundation (vSphere) versions LE5.2: Apply the latest security updates provided by VMware to address this authentication bypass vulnerability.

Consider changing the default 'ESXi Admins' Active Directory group to mitigate the risk of unauthorized access.

Implement strong authentication measures, such as multi-factor authentication, to enhance security.

Segment your network to limit the potential impact of a successful exploit.

Monitor for suspicious activity related to the 'ESXi Admins' group and unusual ESXi activity.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-05045
CVE-2024-37085

Affected Products

Vmware Esxi