Vulnerability Intelligence Report
VMware ESXi Authentication Bypass Vulnerability
CVE-2024-37085
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
6.8
MEDIUM
Exploitability:1.0
Impact Score:5.9
EPSS Probability:26.77%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-305 ↗CWE-305 Authentication Bypass by Primary Weakness
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| vmware | cloud_foundation | all |
| vmware | esxi | 7.0, 8.0 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VMware by Broadcom · Vendor · USA |
| Reserved | 2024-06-03T05:40:17 |
| Published | 2024-06-25T14:16:01 |
| Patch Date | 2024-06-25 |
| Last Updated | 2025-10-21T22:56:21 |
Community Chatter & Buzz