VYPR
Medium severity6.8CISA KEVNVD Advisory· Published Jun 25, 2024· Updated Jun 17, 2026

CVE-2024-37085

CVE-2024-37085

Description

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

15
  • cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
    Range: >=4.0,<5.2
  • VMware/Esxi13 versions
    cpe:2.3:o:vmware:esxi:7.0:*:*:*:*:*:*:*+ 12 more
    • cpe:2.3:o:vmware:esxi:7.0:*:*:*:*:*:*:*
    • cpe:2.3:o:vmware:esxi:8.0:-:*:*:*:*:*:*
    • cpe:2.3:o:vmware:esxi:8.0:a:*:*:*:*:*:*
    • cpe:2.3:o:vmware:esxi:8.0:b:*:*:*:*:*:*
    • cpe:2.3:o:vmware:esxi:8.0:c:*:*:*:*:*:*
    • cpe:2.3:o:vmware:esxi:8.0:update_1:*:*:*:*:*:*
    • cpe:2.3:o:vmware:esxi:8.0:update_1a:*:*:*:*:*:*
    • cpe:2.3:o:vmware:esxi:8.0:update_1c:*:*:*:*:*:*
    • cpe:2.3:o:vmware:esxi:8.0:update_1d:*:*:*:*:*:*
    • cpe:2.3:o:vmware:esxi:8.0:update_2:*:*:*:*:*:*
    • cpe:2.3:o:vmware:esxi:8.0:update_2b:*:*:*:*:*:*
    • cpe:2.3:o:vmware:esxi:8.0:update_2c:*:*:*:*:*:*
    • (no CPE)

Patches

Vulnerability mechanics

References

2

News mentions

2