HIGH

CVE-2024-37085

Vmware Cloud Foundation 2024-06-25 CVSS v3.1
CVSS
7.2
KEV

Description

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.

Summary dbcve.org

VMware ESXi contains an authentication bypass vulnerability where a malicious actor with sufficient Active Directory permissions can gain full access to an ESXi host previously configured to use AD for user management by re-creating the configured AD group (default 'ESXi Admins') after it was deleted from AD. The ESXi host will automatically authenticate any user in the recreated group as a privileged administrator, bypassing normal access controls.

Mitigation

Organizations should rename the default ESXi Admins group to a unique, non-predictable name in Active Directory, audit and restrict AD permissions to prevent unauthorized group creation, and review all ESXi host AD configurations to ensure they reference specific, unique group SIDs rather than group names.

Patch Commit

Weakness (CWE)

CWE-287 Improper Authentication
CWE-305

EPSS Score

26.77%
Probability of exploitation in next 30 days
98th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE