CVE-2024-37085 KEV
6.8
MEDIUM · CVSS 3.1 · EPSS 26.8% (pctl 98)
Patch first
On CISA KEV — known exploited in the wild, due 2024-08-20.
Description
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.
Scoring
| CVSS | 6.8 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 26.77% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | yes — remediate by 2024-08-20 |
| Public exploit | none known |
| Published | 2024-06-25 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | VMware ESXi Authentication Bypass Vulnerability |
|---|---|
| Added | 2024-07-30 |
| Due | 2024-08-20 |
| Vendor / product | VMware / ESXi |
| Ransomware use | known |
Affected (2)
| Vendor | Product |
|---|---|
| vmware | cloud foundation |
| vmware | esxi |
References
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24505
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24505
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-37085
→ the Explorer · watch your stack · NVD