CVE-2024-37085
Description
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.
Summary dbcve.org
VMware ESXi contains an authentication bypass vulnerability where a malicious actor with sufficient Active Directory permissions can gain full access to an ESXi host previously configured to use AD for user management by re-creating the configured AD group (default 'ESXi Admins') after it was deleted from AD. The ESXi host will automatically authenticate any user in the recreated group as a privileged administrator, bypassing normal access controls.
Mitigation
Organizations should rename the default ESXi Admins group to a unique, non-predictable name in Active Directory, audit and restrict AD permissions to prevent unauthorized group creation, and review all ESXi host AD configurations to ensure they reference specific, unique group SIDs rather than group names.