CVE-2024-37085: lessons in ESXi and Active Directory administrator permissions
Reference analysis of Microsoft's 2024 research, with questions for reviewing access and protecting virtualization infrastructure.
Updated: · Vietnam time (UTC+7)

Microsoft's research was compared with vendor advisory VMSA-2024-0013. This does not claim that the reader's system is being exploited.
Research source dated 29/07/2024. A review of operational lessons, not an alert about a CVE newly discovered in 2026.
Evidence in the original report
Microsoft reported observing CVE-2024-37085 exploitation to obtain administrator access on ESXi hosts joined to Active Directory. The analysis describes administrator-group checking and resulting VM risks. Vendor advisory VMSA-2024-0013 provides affected-version and remediation details.
Technical assessment: control dependencies between layers
A VM's guest OS may be well protected yet still be affected when infrastructure administration is compromised. Asset inventories should include dependencies between directory services, hypervisors, backup systems and operator accounts.
Do not extrapolate one report to every ESXi version. Verify configuration conditions, patches and permissions in the organization's actual environment.
Items to include in a review
- Compare versions against vendor guidance and the update plan.
- Inventory hypervisor administrator groups and identify who can change membership.
- Send management logs to a separate system and assign monitoring of unusual changes.
- Practice VM restoration with dependent components in an isolated network.
- Record test results; absence of alerts does not establish a secure configuration.
Scope of applicability
These are review suggestions, not confirmation of exploitation on an individual system. Preserve artifacts and follow the organization's investigation procedure before concluding a cause.
Sources
Each source's scope and date are recorded separately when available. A citation does not independently verify every assessment.
Update history
· Initial publication with sources and verification limits.
Corrections policy
