Ransomware gangs are loving this dumb but deadly make-me-admin ESXi vulnerability
ID: f8a80032-8ccf-563a-b849-ea80768b50a1
STIX ID: report--f8a80032-8ccf-563a-b849-ea80768b50a1
Feed Name: The Register (Security)
CVE-2024-37085 is a VMware ESXi privilege-escalation flaw that lets any domain user with the ability to create or rename an AD group escalate to ESXi admin by creating/renaming a group called "ESX Admins"; ransomware actors (e.g., Black Basta, Akira, Medusa, Scattered Spider) have actively exploited this to gain full hypervisor control and perform mass encryption. Microsoft and Broadcom have published advisories and patches, but exploitation in the wild and patching/visibility gaps make the vulnerability high-risk for organizations with ESXi hosts joined to Active Directory.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
