logo

Microsoft: Ransomware gangs exploit VMware ESXi auth bypass in attacks

ID: 35ce3e15-6dcb-520f-93e9-bcca37a26d9d

STIX ID: report--35ce3e15-6dcb-520f-93e9-bcca37a26d9d

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-07-29

Date Updated: 2026-07-17

Author: Sergiu Gatlan

...
...

Microsoft disclosed CVE-2024-37085, an ESXi authentication bypass fixed in ESXi 8.0 U3, which permits an actor with elevated AD permissions to recreate an 'ESX Admins' group and obtain full ESXi administrative rights; multiple ransomware operators have exploited this to escalate privileges. The flaw has been used in real-world campaigns (Storm-0506, Storm-1175, Octo Tempest, Manatee Tempest) to deploy Black Basta and Akira ransomware, steal domain credentials, move laterally, and encrypt hypervisors and hosted VMs, causing significant data loss and operational disruption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.