CVE-2024-37085
MEDIUM CISA KEVDescription
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.
CVSS v3.1 Score
CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| vmware | cloud_foundation |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-37085? +
How severe is CVE-2024-37085? +
What products are affected by CVE-2024-37085? +
How do I check if I'm vulnerable to CVE-2024-37085? +
Related Vulnerabilities
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated …
IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19
OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to 2.0.4, a critical authentication vulnerability was identified in OpenLearnX …
PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. Prior to version 0.6.13, if cert_policy …