CVE-2024-37085

MEDIUM CISA KEV
Published Jun 25, 2024 Modified Oct 30, 2025 CWE-287 CWE-305

Description

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.

CVSS v3.1 Score

6.8
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild.

Added: Jul 30, 2024 Remediation due: Aug 20, 2024 Known ransomware use

Weakness Type (CWE)

CWE-287 Improper Authentication
CWE-305 CWE-305

Affected Products

Vendor Product
vmware cloud_foundation
vmware esxi
vmware esxi
vmware esxi
vmware esxi
vmware esxi
vmware esxi
vmware esxi
vmware esxi
vmware esxi
vmware esxi
vmware esxi
vmware esxi

References

Frequently Asked Questions

What is CVE-2024-37085? +
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD. It has a CVSS v3.1 base score of 6.8 (MEDIUM). This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.
How severe is CVE-2024-37085? +
CVE-2024-37085 has a CVSS v3.1 score of 6.8 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2024-37085? +
CVE-2024-37085 affects products from vmware, specifically: cloud_foundation, esxi. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-37085? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-37085 — free, no signup required.

Start Free Scan