MAESTRO Toolkit Exploiting VMware VM Escape Vulnerabilities
ID: 55001ce0-aca2-5284-baba-98a42a25b4a4
STIX ID: report--55001ce0-aca2-5284-baba-98a42a25b4a4
Feed Name: HackRead
In December 2025 Huntress researchers disclosed the MAESTRO toolkit that enabled VM escapes from guest VMs to VMware ESXi hosts by exploiting multiple zero-day vulnerabilities (fixed March 4, 2025). The attackers gained access via stolen SonicWall VPN credentials, targeted the VMX process, used VSOCK for stealth communications, and operated a cross-version exploit covering VMware 5.1 through 8.0; artifacts and simplified Chinese notes suggest a well-resourced, likely Chinese-speaking developer. Organizations are advised to patch immediately and search hosts for signs of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
