Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

CVE-2024-37085 is an authentication bypass affecting VMware ESXi hosts integrated with Active Directory. Microsoft says ransomware operators abused the behavior to gain full host administration after compromising a directory environment; some practitioners objected that the behavior was longstanding and required substantial prior access. Both points matter: this is not an unauthenticated attack against any exposed ESXi server, but it can turn control of Active Directory group operations into control of a hypervisor and its workloads.

What CVE-2024-37085 does

The issue concerns ESXi hosts configured to use Active Directory for user management. Microsoft says that, by default, members of a domain group named “ESX Admins” are treated as full administrators on a joined host. The group is not a built-in Active Directory group, and it does not have to exist when the host joins the domain. Microsoft says the host did not check that the group existed and identified membership by group name rather than security identifier. Microsoft’s technical account and Broadcom’s advisory describe the behavior.

In the scenario Broadcom describes, an actor with sufficient Active Directory permissions can recreate the configured group—ESX Admins by default—after it has been deleted, then gain full access to an affected host. Microsoft also described attackers creating the group and adding a controlled account, renaming another group, or taking advantage of delayed privilege refresh. The prerequisite is meaningful control over directory group operations; the issue is not a drive-by exploit that lets an unauthenticated internet user directly take over an ESXi host.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What Microsoft reported in ransomware incidents

Microsoft reported that Storm-0506, Storm-1175, Octo Tempest, and Manatee Tempest used the technique in ransomware-related activity. In Microsoft’s Storm-0506 case study, the attackers first gained access through Qakbot, escalated privileges on Windows systems, stole domain administrator credentials, and then created ESX Admins membership. Microsoft says the ESXi filesystem was encrypted and hosted virtual machines lost functionality.

That account shows how a compromised enterprise environment can lead to hypervisor disruption; it does not show that attackers can exploit an exposed ESXi host without first obtaining the relevant access. Microsoft Threat Intelligence wrote on July 29, 2024: “Successful exploitation leads to full administrative access to the ESXi hypervisors, allowing threat actors to encrypt the file system of the hypervisor, which could affect the ability of the hosted servers to run and function.” Microsoft also reported that its own incident-response engagements involving targeting and impact of ESXi hypervisors had more than doubled over the preceding three years. That is a measure of Microsoft’s engagements, not a count of all attacks worldwide. Read Microsoft’s incident analysis.

Why some researchers called it a “nothing burger”

Christian Mohn, chief technologist at Proact IT Norge AS, called the CVE a “nothing burger” and described the group behavior as a “feature and not a bug.” As CyberScoop reported, his criticism centered on whether the behavior was new and whether labeling it an exploit overstated the risk when an attacker already needed substantial access. Mohn’s commentary likewise framed the behavior as known rather than a novel flaw.

Rank #2
BZIZU 10Gb PCIe NIC Network Card, Intel 82599EN SFP+, X520-DA1 Compatible
  • GENUINE INTEL 82599EN, THE X520-DA1 SILICON: Sustained 10 Gigabit throughput for NAS transfers, VM migration and iSCSI storage; the link also steps down to 2.5G, 1G and 100M for a slower switch port
  • NO VENDOR LOCK ON THE SFP+ CAGE: Third-party DAC twinax, AOC, 10GBASE-SR multimode and 10GBASE-LR single-mode optics all link up, unlike Intel-branded cards that reject modules they do not recognize
  • PLUG AND PLAY ON PROXMOX, TRUENAS, UNRAID AND ESXI: Also detected by QNAP, Synology, Ubuntu, Debian and CentOS with no driver step; on Windows install the Intel Ethernet Adapter Complete Driver Pack
  • ONLY FOUR PCIe LANES, BOTH BRACKETS IN THE BOX: Seats in any x4, x8 or x16 slot, leaving the rest of the board free; full-height and low-profile brackets both ship, for ATX towers, 1U and 2U racks, mini-ITX
  • AIRFLOW, LIKE ANY 10G CARD: The passive heatsink runs warm by design, so give it case airflow or clip a small fan to it in a silent build; jumbo frames to 9KB and checksum offload run in hardware

That argument addresses novelty and prerequisites, not whether the behavior can be abused after an environment is compromised. Broadcom calls the issue an authentication bypass in ESXi Active Directory integration and rates it Moderate, with a maximum CVSSv3 base score of 6.8. Microsoft supplies an observed ransomware case in which the technique contributed to host encryption and disruption of hosted VMs. The most useful assessment therefore considers three questions rather than relying on labels: whether the behavior was previously documented, what access an attacker needs, and what harm can follow once that access is obtained.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CyberScoop quoted Microsoft director of threat intelligence strategy Sherrod DeGrippo saying: “Ransomware is a significant, high-severity threat being used by threat actors across the landscape, [and] organizations should be aware that exploitation of this vulnerability could result in ransomware or other malicious activity.” This is a warning about consequences in a compromised environment, not evidence of unauthenticated remote access.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to reduce risk on domain-joined ESXi hosts

Microsoft’s July 2024 guidance recommends installing VMware’s security update and layering configuration and monitoring controls. Broadcom’s advisory version matrix lists a fix for ESXi 8.0 and “No Patch Planned” for ESXi 7.0 for this CVE. Because the advisory is the source for that release-specific status, check its current version and the exact build running in your environment before making deployment decisions.

  • Apply the vendor update where available. Use Broadcom’s CVE-2024-37085 advisory to verify affected releases, fixed builds, and current guidance.
  • Review the administrative group configuration. Microsoft recommends ensuring the ESX Admins group exists and is hardened, or assigning a different administrative group. Limit who can create, rename, delete, or change membership of privileged domain groups.
  • Consider disabling automatic administrator addition. If the behavior is not wanted, Microsoft identifies the ESXi advanced host setting Config.HostAgent.plugins.hostsvc.esxAdminsGroupAutoAdd as a control for automatic administrator addition. Validate the setting’s effects against current VMware guidance and operational requirements before changing it.
  • Monitor for directory changes and host activity. Alert on suspicious changes to relevant groups, forward ESXi logs to a SIEM, and use Microsoft’s Defender alerts and hunting queries where applicable.
  • Protect privileged identities. Use MFA for privileged accounts and separate administrative credentials and roles to reduce the chance that a compromise on Windows systems grants control of virtualization infrastructure.

These controls come from Microsoft’s 2024 analysis; organizations should confirm current vendor instructions and configuration details before implementation. Microsoft’s guidance and detection details provide the supporting context.

Rank #4
10Gtek 5Gb/s PCIe Network Card, 100M/2.5G/5G auto-Negotiation, for Windows 8/10/11, Windows Server 2016/2019/2022, Centos 7/8/9, VMware ESXi 6, Ubuntu 20/22, Freebsd 13/14
  • Note: Compatible with low-profile bracket only. Included full-height bracket is not compatible — please disregard.
  • Controller: Realtek RTL8126 controller, equipped with RealWoW technology, supports wake-up and diagnostics, enhancing data stability, Scan the QR code on the NIC to download and install the driver.
  • Interface: PCIe x1 lane, operable in PCIe X1, X4, X8 and X16 slots, not for PCI slots.
  • System: Windows 8/10/11, Windows Server 2016/2019/2022, CentOS7/8/9, VMware ESXi 6, Ubuntu20/22, FreeBSD 13/14.
  • Protocol: PXE, DPDK, WOL, iSCSI, Jumbo Frames, Auto MDIX, IEEE 802.1Q VLAN tagging, IEEE802.3bz (2.5G/5G BASE-T), Full Duplex flow control (IEEE 802.3x), NOT support FCoE.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.