Exposure Watch
Compare vulnerabilities and exposed services against actual assets, versions and configurations.
CVE · Reference material
CVE-2024-37085 · VMware ESXi
Microsoft reported exploitation in 2024. This is not a new 2026 CVE and does not confirm that a reader's system is affected.
Read the analysis and vendor sources| Category | Review question | Actual observations |
|---|---|---|
| Exposed services | Which services actually need Internet access? | No measurement data |
| RDP | Are access paths, MFA and source restrictions controlled? | No measurement data |
| VPN / Firewall | Have versions, configurations and administrator accounts been reviewed? | No measurement data |
| NAS | How are management interfaces, applications and data permissions protected? | No measurement data |
| ESXi / Hyper-V | Who can administer hosts and change configuration? | No measurement data |
| SQL Server | Is the service exposed externally, and are account privileges limited? | No measurement data |
| Backup infrastructure | Are backup permissions and environments separated, and have restores been tested? | No measurement data |
This is a review checklist, not the result of scanning an organization's infrastructure.
Sources
Microsoft Threat Intelligence — CVE-2024-3708529/07/2024 · Analysis of ESXi exploitation observed by Microsoft.
Broadcom — VMSA-2024-00132024 · Vendor advisory; check affected versions and mitigations.
Each source's scope and date are recorded separately when available. A citation does not independently verify every assessment.