Executive brief
VMware ESXi contains an authentication bypass vulnerability where a malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host. The attack involves re-creating the 'ESXi Admins' AD group after it has been deleted, allowing the actor to bypass authentication on hosts configured to use AD for user management.
Affected products
- VMware ESXi 7.0, 8.0
- VMware Cloud Foundation 4.0 to 5.2
Timeline
- 2024-07-30: disclosed
- 2024-07-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-07-30: patched: Broadcom/VMware released security advisory and patches.