Horizon Alert
Summary of the vulnerability and why it matters
VMware ESXi systems that use Active Directory for user management are vulnerable to an authentication bypass. This flaw allows a malicious actor with specific Active Directory permissions to regain full administrative access to an ESXi host. This can occur if the administrative group, typically named 'ESXi Admins', is deleted from Active Directory and then recreated by the actor. The potential impact includes unauthorized access and control over critical infrastructure.
- VMware ESXi with Active Directory integration
- Authentication bypass via AD group recreation
- Unauthorized access to ESXi hosts
Attack Path
How an attacker could exploit the issue
An attacker could gain unauthorized access to an ESXi host by exploiting a vulnerability related to Active Directory group management. This attack bypasses authentication by re-creating a specific Active Directory group after it has been deleted. Sufficient permissions within Active Directory are required for the attacker to execute this action.
- Network exposure required.
- Attacker with AD group permissions.
- Recreate AD group for access.
Live Threat
Current exploitation, exposure, and threat context
VMware ESXi hosts that use Active Directory for user management are susceptible to an authentication bypass. An attacker with adequate Active Directory permissions could exploit this by recreating a specific AD group after it has been deleted. This action could grant the attacker full access to the ESXi host.
- Attackers need specific AD permissions.
- Exploitation requires prior AD group deletion.
- Business risk is high due to full host access.
Priority actions
Operational Fix
Recommended remediation, mitigation, and detection steps
An authentication bypass vulnerability exists in VMware ESXi, allowing a malicious actor with specific Active Directory permissions to gain full access to an ESXi host. This can occur if the configured Active Directory group for ESXi administrators is deleted and then recreated. The potential business risk involves unauthorized access to critical infrastructure, leading to data compromise or service disruption.
- Identify ESXi hosts configured for Active Directory.
- Review and secure Active Directory group permissions.
- Apply vendor updates and monitor system logs.