Database/Kernel, userspace & hypervisor
VMware ESXi: AD-integrated ESXi grants full host admin to any member of a re-created "ESX Admins" group
CVE-2024-37085Kernel, userspace & hypervisorKnown exploitedcurated
Impact
AD-integrated ESXi grants full host admin to any member of a re-created "ESX Admins" group - used by Akira and Black Basta to mass-encrypt VMs [KEV]
Who can reach it
Attacker with Active Directory write access (post-initial-access, not tenant-facing)
What to do
Patch ESXi and stop using AD for ESXi user management. Configuration change, not just a binary update - the real fix is removing the AD trust from the hypervisor plane
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.