CISA warns of VMware ESXi bug exploited in ransomware attacks

Share:

CISA has ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their servers against a VMware ESXi authentication bypass vulnerability exploited in ransomware attacks.

Broadcom subsidiary VMware fixed this flaw (CVE-2024-37085) discovered by Microsoft security researchers on June 25 with the release of ESXi 8.0 U3.

CVE-2024-37085 allows attackers to add a new user to the ‘ESX Admins’ group—not present by default but can be added after gaining high privileges on the ESXi hypervisor—which will automatically be assigned full administrative privileges.

Even though successful exploitation would require user interaction and high privileges to pull off, and VMware rated the vulnerability as medium-severity, Microsoft revealed on Monday week that several ransomware gangs are already exploiting it to escalate to full admin privileges on domain-joined hypervisors.

Once they gain admin permissions, they steal sensitive data from VMs, move laterally through victims’ networks, and then encrypt the ESXi hypervisor’s file system, causing outages and disrupting business operations.

So far, CVE-2024-37085 has been exploited by ransomware operators tracked as Storm-0506, Storm-1175, Octo Tempest, and Manatee Tempest to deploy Akira and Black Basta ransomware.

Federal agencies have three weeks to secure vulnerable systems

Following Microsoft’s report, CISA has added the security vulnerability to its ‘Known Exploited Vulnerabilities’ catalog, serving as a warning that threat actors are leveraging it in attacks.

Federal Civilian Executive Branch Agencies (FCEB) agencies now have three weeks until August 20 to secure their systems against ongoing CVE-2024-37085 exploitation, according to the binding operational directive (BOD 22-01) issued in November 2021.

Although this directive only applies to federal agencies, the cybersecurity agency strongly urged all organizations to prioritize fixing the flaw and thwart ransomware attacks that could target their networks.

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” CISA warned.

For years, ransomware operations have shifted their focus to targeting their victims’ ESXi virtual machines (VMs), particularly after the victims have started using them to store sensitive data and host critical applications.

However, until now, they’ve primarily used Linux lockers designed to encrypt VMs rather than exploiting specific security vulnerabilities in ESXi (such as CVE-2024-37085), even though doing so could provide a faster way to access victims’ hypervisors.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:44 am, Jun 20, 2025
weather icon 26°C
L: 25° | H: 27°
overcast clouds
Humidity: 54 %
Pressure: 1023 mb
Wind: 5 mph E
Wind Gust: 8 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:42 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
25° | 27°°C 0 mm 0% 11 mph 56 % 1023 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
18° | 32°°C 0.43 mm 43% 11 mph 62 % 1020 mb 0 mm/h
Sun Jun 22 10:00 pm
weather icon
17° | 26°°C 0.86 mm 86% 15 mph 87 % 1014 mb 0 mm/h
Mon Jun 23 10:00 pm
weather icon
14° | 23°°C 0.2 mm 20% 14 mph 80 % 1017 mb 0 mm/h
Tue Jun 24 10:00 pm
weather icon
14° | 25°°C 0 mm 0% 16 mph 76 % 1017 mb 0 mm/h
Today 1:00 pm
weather icon
26° | 26°°C 0 mm 0% 9 mph 54 % 1023 mb 0 mm/h
Today 4:00 pm
weather icon
26° | 26°°C 0 mm 0% 11 mph 48 % 1023 mb 0 mm/h
Today 7:00 pm
weather icon
22° | 23°°C 0 mm 0% 11 mph 46 % 1022 mb 0 mm/h
Today 10:00 pm
weather icon
20° | 20°°C 0 mm 0% 8 mph 56 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
18° | 18°°C 0 mm 0% 5 mph 62 % 1020 mb 0 mm/h
Tomorrow 4:00 am
weather icon
18° | 18°°C 0 mm 0% 5 mph 60 % 1019 mb 0 mm/h
Tomorrow 7:00 am
weather icon
21° | 21°°C 0 mm 0% 6 mph 54 % 1019 mb 0 mm/h
Tomorrow 10:00 am
weather icon
28° | 28°°C 0 mm 0% 9 mph 34 % 1018 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,212.21
0.95%
Ethereum(ETH)
€2,221.05
0.48%
Tether(USDT)
€0.87
-0.01%
XRP(XRP)
€1.89
0.29%
Solana(SOL)
€128.91
1.33%
USDC(USDC)
€0.87
0.01%
Dogecoin(DOGE)
€0.148233
0.00%
Shiba Inu(SHIB)
€0.000010
0.82%
Pepe(PEPE)
€0.000009
-0.72%
Scroll to Top