Microsoft calls out apparent ESXi vulnerability that some researchers say is a ‘nothing burger’
ID: a40d8337-953a-599e-a925-4408c4f003f6
STIX ID: report--a40d8337-953a-599e-a925-4408c4f003f6
Feed Name: CyberScoop
Microsoft researchers reported that CVE-2024-37085 affecting VMware ESXi/vCenter is being abused in the wild to create an "ESX Admins" group and add attacker-controlled users, granting full hypervisor control that enables mass VM encryption, lateral movement, and data exfiltration; multiple ransomware families (Black Basta, Babuk, Lockbit, Kuiper) and criminal clusters (including Storm-0506 and Scattered Spider/Octo Tempest) have used the technique, prompting VMware patches and CISA listing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
