“VM Isolation is Not Absolute”: Researchers Unmask Sophisticated ESXi “Maestro” Exploit
ID: 7414bd81-0984-56d6-b56e-43e4ba3c9970
STIX ID: report--7414bd81-0984-56d6-b56e-43e4ba3c9970
Feed Name: securityonline.info
Threat Score
Huntress details a high-impact December 2025 intrusion where attackers escaped a guest VM to fully compromise VMware ESXi hosts using a toolkit (MAESTRO), an unsigned kernel driver (MyDriver.sys) and a stealthy VSOCK-based backdoor (VSOCKpuppet); the report indicates the exploit likely existed as a zero-day since February 2024 and affects a wide range of ESXi builds (5.1–8.0), emphasizing the need for aggressive patching and host-level monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
