logo

Microsoft calls out apparent ESXi vulnerability that some researchers say is a ‘nothing burger’ 

ID: a40d8337-953a-599e-a925-4408c4f003f6

STIX ID: report--a40d8337-953a-599e-a925-4408c4f003f6

Feed Name: CyberScoop

Threat Score
78/100

Date Published: 2024-07-30

Date Updated: 2026-04-21

Author: AJ Vicens

...
...

Microsoft researchers reported that CVE-2024-37085 affecting VMware ESXi/vCenter is being abused in the wild to create an "ESX Admins" group and add attacker-controlled users, granting full hypervisor control that enables mass VM encryption, lateral movement, and data exfiltration; multiple ransomware families (Black Basta, Babuk, Lockbit, Kuiper) and criminal clusters (including Storm-0506 and Scattered Spider/Octo Tempest) have used the technique, prompting VMware patches and CISA listing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.