CVE-2024-37085 — Vmware Cloud Foundation
CISA KEVRansomwareAs of 2025-10-21, CVE-2024-37085 is a MEDIUM-severity vulnerability in Vmware Cloud Foundation, CVSS v3.1 6.8, EPSS 75.6% (98.9th percentile). It is listed in the CISA Known Exploited Vulnerabilities catalog (added 2024-07-30), with a US federal remediation deadline of 2024-08-20, and CISA links it to known ransomware campaigns. Threadlinqs Intelligence links 2 tracked threat campaigns to CVE-2024-37085, most recently “The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework (400+ processes, 8 BYOVD variants) and 90% affiliate payouts”.
Last updated: 2025-10-21
What is CVE-2024-37085?
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.
The record classifies CVE-2024-37085 under weakness classes CWE-287, CWE-305. Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs high-privilege credentials, needs a user to take an action first, and has high impact on confidentiality, integrity, availability. 2 affected-product entries are recorded, across 1 vendor, listed below. The identifier was first published 810 days ago.
Severity and exploitation probability
- CVSS v3.1 base score
- 6.8 — MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H - EPSS (FIRST)
- 75.6% probability of exploitation in the next 30 days, higher than 98.9% of all scored CVEs
- CISA KEV
- Listed since 2024-07-30, federal remediation deadline 2024-08-20 — used in known ransomware campaigns
- Threadlinqs priority
- 10/10 — CISA lists it as used in ransomware, which Threadlinqs scores at the maximum
- Published
- 2024-06-25, last modified 2025-10-21
Is CVE-2024-37085 being exploited?
CISA added CVE-2024-37085 to the Known Exploited Vulnerabilities catalog on 2024-07-30, which means the agency holds evidence of exploitation in the wild; US federal civilian agencies had to remediate it by 2024-08-20 under BOD 22-01. CISA flags the vulnerability as one used in known ransomware campaigns. It currently carries a trending score of 40 in the Threadlinqs vulnerability feed.
Affected products and versions
- Vmware: Cloud Foundation, Esxi
How to fix CVE-2024-37085
The record marks a vendor fix as available for CVE-2024-37085. Patch reference: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24505. Vendor advisory: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24505. Because CVE-2024-37085 is KEV-listed, US federal civilian agencies were required to apply the vendor fix, or stop using the product, by 2024-08-20. Apply the vendor fix referenced above to every affected product listed in this record, then confirm the running version against the vendor advisory.
Threat activity tracking CVE-2024-37085
2 tracked threats in the Threadlinqs corpus reference CVE-2024-37085, either in the campaign’s CVE list or as an indicator on the campaign record.
- The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework (400+ processes, 8 BYOVD variants) and 90% affiliate payouts — HIGH · 2026-07-14
- Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow Copy Deletion (SANS ISC Forensic Reconstruction, May 2026) — HIGH · 2026-05-27
Sources
Seeded from cveorg and not yet processed by the Threadlinqs enrichment pipeline, so blank CVSS, EPSS or KEV fields above mean NOT MEASURED rather than measured-absent.
← all vulnerabilities · Markdown version · Threadlinqs Intelligence