Microsoft Uncovers Major ESXi Hypervisor Flaw: Ransomware Operators Rejoice!
Microsoft researchers have uncovered a critical ESXi hypervisor vulnerability exploited by ransomware operators to gain full administrative access. This allows them to encrypt systems, access hosted VMs, and move laterally within networks. Apply VMware updates immediately to mitigate this risk.

Hot Take:
Looks like ransomware operators are throwing a virtual house party in VMware’s ESXi hypervisors, and Microsoft just showed up with the noise complaint. Time to break out the security updates, folks!
Key Points:
– Microsoft researchers identified a critical vulnerability (CVE-2024-37085) in ESXi hypervisors.
– Ransomware groups like Storm-0506 and Black Basta are exploiting this to gain full administrative permissions.
– The vulnerability stems from improper validation of a domain group named “ESX Admins.”
– VMware has released a security update to address the issue.
– Microsoft urges immediate application of the security update and provides additional mitigation strategies.
Membership Required
You must be a member to access this content.