CVE-2024-37085 - CVE House
Back to Database
Status published Medium CVE-2024-37085

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with...

Vulnerability Description

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-37085

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

VMware ESXi, VMware Cloud Foundation
Vulnerable Versions:
8.0, 7.0, 5.x, 4.x

Timeline

Official Publish: June 25th, 2024
Last Modified: October 21st, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.