Hypervisor Vulnerability: The Risk You Can’t Patch Yourself
In 2024, Microsoft’s own security researchers documented ransomware operators actively exploiting a hypervisor vulnerability, CVE-2024-37085, to gain full administrative control over ESXi hosts and mass-encrypt every virtual machine running on them. Critically, the businesses affected had no way to patch this themselves. That is because the vulnerability lived in infrastructure they did not control. This […]
