CVE-2024-37085

More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
Net group "babyk" /add
During the investigation of one of the incidents, we discovered the exploitation of the CVE-2024-37085 vulnerability. It allows an attacker to gain full control over a VMware ESXi hypervisor joined to a domain 😠
The vulnerability lies in the fact that users who are members of a group named ESX Admins have maximum access rights to the hypervisor by default. This group does not exist in the domain by default, so the attacker needs to take over an account that has the rights to create a group and add users to it.
✏️ The CVE-2024-37085 vulnerability was described by Microsoft in July 2024.
The article mentions the exploitation of this flaw by the operators of the Akira and Black Basta ransomware. There is no information in public reports about the use of the vulnerability in attacks on Russian organizations.
👤 In the case we are examining, the attackers managed to gain access to the domain controller and take over an account with the necessary rights. After that, they created the ESX Admins group and added a user to it by running the following commands:
net group "ESX Admins" /add /domain
net group "ESX Admins" superuser /add /do
Using this user’s identity, the intruders subsequently logged into the hypervisor and encrypted the files and disks of virtual machines using Babyk.
Security log events can help in detecting the exploitation of CVE-2024-37085:
• 4727 — creation of an Active Directory security group named ESX Admins;
• 4737 — modification of an Active Directory security group (renaming the group to ESX Admins);
• 4728 — addition of a user to an Active Directory security group named ESX Admins.
To fix the described vulnerability, it is recommended to install the latest security updates for VMware ESXi.
#dfir #cve #detect #win
@ptescalator
More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…



