Database/Kernel, userspace & hypervisor
VMware ESXi: AD-integrated ESXi grants full host admin to any member of a re-created "ESX Admins" group
CVSS 6.8CVE-2024-37085Kernel, userspace & hypervisorKnown exploitedcurated
Impact
AD-integrated ESXi grants full host admin to any member of a re-created "ESX Admins" group - used by Akira and Black Basta to mass-encrypt VMs [KEV]
Who can reach it
Attacker with Active Directory write access (post-initial-access, not tenant-facing)
What to do
Patch ESXi and stop using AD for ESXi user management. Configuration change, not just a binary update - the real fix is removing the AD trust from the hypervisor plane
References
Related entries
- VMware ESXi: Arbitrary kernel write from the VMX process - sandbox escape completing the zero-day chainCVE-2025-22225 · VMware ESXiHigh
- Linux kernel (drivers/pci): A Downstream Port Containment event and a device removal happening at the same time leaveCVE-2024-42302 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/pci): A pci_slot holds an uncounted pointer to the pci_bus below it, and on hot removal the busCVE-2024-53194 · Linux kernel (drivers/pci)Medium
- OpenSSH (client): Machine-in-the-middle against the client when VerifyHostKeyDNS is enabledCVE-2025-26465 · OpenSSH (client)Medium
- Xen AMD-Vi (AMD IOMMU) interrupt remapping table handling: On AMD-Vi platforms Xen used a single interrupt remappingCVE-2013-0153 · Xen AMD-Vi (AMD IOMMU) interrupt remapping table handlingMedium
- Linux kernel (eBPF verifier): kernel/bpf/verifier.c mishandles pointer types - unprivileged BPF to local rootCVE-2022-23222 · Linux kernel (eBPF verifier)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.