logo

MAESTRO Toolkit Exploiting VMware VM Escape Vulnerabilities

ID: 55001ce0-aca2-5284-baba-98a42a25b4a4

STIX ID: report--55001ce0-aca2-5284-baba-98a42a25b4a4

Feed Name: HackRead

Threat Score
85/100

Date Published: 2026-01-09

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

In December 2025 Huntress researchers disclosed the MAESTRO toolkit that enabled VM escapes from guest VMs to VMware ESXi hosts by exploiting multiple zero-day vulnerabilities (fixed March 4, 2025). The attackers gained access via stolen SonicWall VPN credentials, targeted the VMX process, used VSOCK for stealth communications, and operated a cross-version exploit covering VMware 5.1 through 8.0; artifacts and simplified Chinese notes suggest a well-resourced, likely Chinese-speaking developer. Organizations are advised to patch immediately and search hosts for signs of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.