GPU VulnDB

Database/Kernel, userspace & hypervisor

VMware ESXi: AD-integrated ESXi grants full host admin to any member of a re-created "ESX Admins" group

CVE-2024-37085Kernel, userspace & hypervisorKnown exploitedcurated

Impact

AD-integrated ESXi grants full host admin to any member of a re-created "ESX Admins" group - used by Akira and Black Basta to mass-encrypt VMs [KEV]

Who can reach it

Attacker with Active Directory write access (post-initial-access, not tenant-facing)

What to do

Patch ESXi and stop using AD for ESXi user management. Configuration change, not just a binary update - the real fix is removing the AD trust from the hypervisor plane

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.