Ransomware operators exploit ESXi hypervisor vulnerability for mass encryption
ID: 2be33c2c-b8a4-5a30-a6bb-d32472c42fed
STIX ID: report--2be33c2c-b8a4-5a30-a6bb-d32472c42fed
Feed Name: Microsoft Security
Microsoft researchers disclosed CVE-2024-37085, a vulnerability in domain-joined VMware ESXi hypervisors where any member of a domain group named "ESX Admins" is granted full hypervisor administrative privileges by name (not SID). Attackers have abused this by creating or renaming groups and adding accounts, enabling elevation to full ESXi admin access; Microsoft observed exploitation by multiple ransomware operators (including Storm-0506) leading to ESXi filesystem encryption and mass impact to hosted VMs. The post details observed attack chains (initial access via Qakbot and credential theft tools), recommended VMware updates and mitigations, Defender detections, and hunting queries for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
