« Volver al listado

CVE-2024-37085

Estado: AnalizadaAlta (7.2)⚠ Explotación activa

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CISA KEV — explotada activamente

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Explotación de servicio remoto (AD integrado en ESXi) con altos privilegios (PR:H). Impacto: acceso de cuenta de dominio mediante recreación de grupo AD autorizado, ganando control total del host.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-37085",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-37085",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "active"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-07-31T03:55:22.790428Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@vmware.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.2,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "VMware ESXi",
          "versions": [
            {
              "status": "affected",
              "version": "8.0",
              "lessThan": "ESXi80U3-24022510",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "7.0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "n/a",
          "product": "VMware Cloud Foundation",
          "versions": [
            {
              "status": "affected",
              "version": "5.x"
            },
            {
              "status": "affected",
              "version": "4.x"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:vmware:esxi:7.0:-:*:*:*:*:*:*"
          ],
          "vendor": "vmware",
          "product": "esxi",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:vmware:cloud_foundation:5.0:*:*:*:*:*:*:*"
          ],
          "vendor": "vmware",
          "product": "cloud_foundation",
          "versions": [
            {
              "status": "affected",
              "version": "5.0",
              "lessThan": "5.2",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:vmware:cloud_foundation:4.0:*:*:*:*:*:*:*"
          ],
          "vendor": "vmware",
          "product": "cloud_foundation",
          "versions": [
            {
              "status": "affected",
              "version": "4.0",
              "lessThan": "5.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:vmware:esxi:8.0:*:*:*:*:*:*:*"
          ],
          "vendor": "vmware",
          "product": "esxi",
          "versions": [
            {
              "status": "affected",
              "version": "8.0",
              "lessThan": "ESXi80U3-24022510",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-06-25T15:15:12.377",
  "references": [
    {
      "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24505",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24505",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-37085",
      "tags": [
        "US Government Resource"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-305"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously  configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html  by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD."
    },
    {
      "lang": "es",
      "value": "VMware ESXi contiene una vulnerabilidad de omisión de autenticación. Un actor malicioso con suficientes permisos de Active Directory (AD) puede obtener acceso completo a un host ESXi que se configuró previamente para usar AD para la administración de usuarios https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts -to-active-directory.html recreando el grupo de AD configurado ('Administradores de ESXi' de forma predeterminada) después de eliminarlo de AD."
    }
  ],
  "lastModified": "2026-06-17T07:37:43.940",
  "cisaActionDue": "2024-08-20",
  "cisaExploitAdd": "2024-07-30",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7FA8DFE6-9C74-4711-A8AF-3B170876A1F9",
              "versionEndExcluding": "5.2",
              "versionStartIncluding": "4.0"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "48D2E2D5-A0B8-4AF1-BF4A-30154F754C94"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:8.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A1A402A-9262-4B97-A0B7-E5AE045E394D"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:8.0:a:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FE44B379-9943-4DD1-8514-26F87482AFA8"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:8.0:b:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2A797377-8945-4D75-AA68-A768855E5842"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:8.0:c:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "79D84D76-54BE-49E9-905C-7D65B4B42D68"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:8.0:update_1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F8767F7-7C3D-457D-9EAC-E8A30796F751"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:8.0:update_1a:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "29AF8474-2D7A-4C5A-82B9-7A873AD90C2E"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:8.0:update_1c:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7781A2CA-D927-48CD-9932-AE42B7BA1EFE"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:8.0:update_1d:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "18FD08C9-5895-4BF4-BBE0-C2DDA5F6B836"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:8.0:update_2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "360C1B71-5360-4379-B0DE-63BB8F5E6DA2"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:8.0:update_2b:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B16ED7C1-9881-452A-8BE0-EDDEAEFE3D7B"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esxi:8.0:update_2c:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED92209F-FBD6-43F9-9A15-3842B139FCC9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com",
  "cisaRequiredAction": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
  "cisaVulnerabilityName": "VMware ESXi Authentication Bypass Vulnerability"
}