CISA warns of VMware ESXi bug exploited in ransomware attacks

Teilen:

CISA has ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their servers against a VMware ESXi authentication bypass vulnerability exploited in ransomware attacks.

Broadcom subsidiary VMware fixed this flaw (CVE-2024-37085) discovered by Microsoft security researchers on June 25 with the release of ESXi 8.0 U3.

CVE-2024-37085 allows attackers to add a new user to the ‘ESX Admins’ group—not present by default but can be added after gaining high privileges on the ESXi hypervisor—which will automatically be assigned full administrative privileges.

Even though successful exploitation would require user interaction and high privileges to pull off, and VMware rated the vulnerability as medium-severity, Microsoft revealed on Monday week that several ransomware gangs are already exploiting it to escalate to full admin privileges on domain-joined hypervisors.

Once they gain admin permissions, they steal sensitive data from VMs, move laterally through victims’ networks, and then encrypt the ESXi hypervisor’s file system, causing outages and disrupting business operations.

So far, CVE-2024-37085 has been exploited by ransomware operators tracked as Storm-0506, Storm-1175, Octo Tempest, and Manatee Tempest to deploy Akira and Black Basta ransomware.

Federal agencies have three weeks to secure vulnerable systems

Following Microsoft’s report, CISA has added the security vulnerability to its ‘Known Exploited Vulnerabilities’ catalog, serving as a warning that threat actors are leveraging it in attacks.

Federal Civilian Executive Branch Agencies (FCEB) agencies now have three weeks until August 20 to secure their systems against ongoing CVE-2024-37085 exploitation, according to the binding operational directive (BOD 22-01) issued in November 2021.

Although this directive only applies to federal agencies, the cybersecurity agency strongly urged all organizations to prioritize fixing the flaw and thwart ransomware attacks that could target their networks.

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” CISA warned.

For years, ransomware operations have shifted their focus to targeting their victims’ ESXi virtual machines (VMs), particularly after the victims have started using them to store sensitive data and host critical applications.

However, until now, they’ve primarily used Linux lockers designed to encrypt VMs rather than exploiting specific security vulnerabilities in ESXi (such as CVE-2024-37085), even though doing so could provide a faster way to access victims’ hypervisors.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
10:37 pm, Juni 22, 2025
Wetter-Symbol 20°C
L: 18° | H: 20°
wenige Wolken
Luftfeuchtigkeit: 67 %
Druck: 1011 mb
Wind: 12 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 20%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 10:00 pm
Wetter-Symbol
18° | 20°°C 0.66 mm 66% 14 mph 77 % 1016 mb 0 mm/h
Di. Juni 24 10:00 pm
Wetter-Symbol
13° | 24°°C 0.2 mm 20% 14 mph 81 % 1016 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
16° | 28°°C 0 mm 0% 11 mph 88 % 1014 mb 0 mm/h
Do. Juni 26 10:00 pm
Wetter-Symbol
17° | 25°°C 1 mm 100% 15 mph 84 % 1018 mb 0 mm/h
Fr. Juni 27 10:00 pm
Wetter-Symbol
15° | 28°°C 0 mm 0% 15 mph 70 % 1020 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 13 mph 70 % 1011 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
17° | 18°°C 0.66 mm 66% 14 mph 77 % 1011 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
15° | 15°°C 0.2 mm 20% 13 mph 64 % 1013 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 13 mph 45 % 1014 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
20° | 20°°C 0 mm 0% 13 mph 32 % 1014 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 14 mph 30 % 1014 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 14 mph 40 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 11 mph 55 % 1016 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€86,238.92
-2.65%
Ethereum(ETH)
€1,896.89
-7.08%
Fesseln(USDT)
€0.87
0.02%
XRP(XRP)
€1.71
-4.18%
Solana(SOL)
€112.39
-5.02%
USDC(USDC)
€0.87
0.01%
Dogecoin(DOGE)
€0.128487
-5.28%
Shiba Inu(SHIB)
€0.000009
-4.67%
Pepe(PEPE)
€0.000008
-7.80%
Peanut das Eichhörnchen(PNUT)
€0.218233
13.10%
Nach oben scrollen