Hackers Exploit ESXi Flaw for Devastating Ransomware Attacks
ID: 8958b82d-b754-5c7f-9a08-b7a589bb0671
STIX ID: report--8958b82d-b754-5c7f-9a08-b7a589bb0671
Feed Name: Cyber Press
Microsoft and VMware disclosed CVE-2024-37085, a vulnerability in domain-joined ESXi hypervisors that improperly grants full administrative privileges to members of a domain group named "ESX Admins". Ransomware groups including Storm-0506 are actively exploiting this flaw—by creating or renaming groups and adding users—to gain hypervisor control, encrypt virtual machines, exfiltrate data, and move laterally; the report outlines the exploitation methods, a broader attack chain (Qakbot, CVE-2023-28252, Cobalt Strike, Pypykatz, SystemBC), and recommends applying VMware's patch immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
