logo

Use one Virtual Machine to own them all — active exploitation of ESXicape

ID: 44ba7779-952a-5dea-8987-4be433f1ad09

STIX ID: report--44ba7779-952a-5dea-8987-4be433f1ad09

Feed Name: DoublePulsar

Threat Score
85/100

Date Published: 2025-03-05

Date Updated: 2026-04-19

Author: Kevin Beaumont

...
...

Executive summary: A critical hypervisor escape vulnerability in VMware ESXi/vCenter allows attackers who compromise a VM to break out of the VM, access cluster storage and other VMs, and manipulate domain resources; Microsoft observed the exploit in the wild and unpatched ESXi deployments (including managed providers and private clouds) are at significant risk, often leveraged in ransomware incidents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.