Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-37085 — Python exploit for CVE-2024-37085, an authentication bypass in domain-joined ESXi hypervisors, enabling unauthenticated shell upload and full administrator access. | Kitploit
Tools/GitHubGitHub/wtn-arny/cve-2024-37085
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingAuthentication
GitHubwtn-arny/cve-2024-37085

CVE-2024-37085

Python exploit for CVE-2024-37085, an authentication bypass in domain-joined ESXi hypervisors, enabling unauthenticated shell upload and full administrator access.

View Repository
22 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-37085          Hits


unauthenticated shell upload to full administrator on domain-joined esxi hypervisors.

Download ESXI[VORTEX]

Details:

an authentication bypass which leads to shell upload in context of vpxuser leading to full administrative permission on domain-joined ESXI hypervisors.
in order to exploit this vulnerability the ESXI shell must to enabled.

Exploit:

The exploitation of this vulnerability needs to perform few steps in order to acheive full administrator controll.
which all the steps are handled by a single python script.
to exploit this vuln you need to chose the methods which are used in this script
with the --full or -f argument the script will try to get a shell with full administrative permissions
and if the --dc or -d argument is not provided then the script, will only upload a shell to the target
if the argmunet for shell is provided (--shel or -s) if not provided then it'll use the default shell
which you can execute command with post request using param cmd=[command].

root@kitploit:~
python3.10 and above are requiered.
this script doesnt supports multithreadin for some reasons

Info:

as usaul I asking you, before buying or even considering to buy, make sure to verify the DOWNLOAD links provided here via this email: [email protected]
and also upon the request I will provide prove.
but dont ask me to send you the script before making the payment, or sending your specific target to test it for you and/or give you shell
Other payment methods are support via the email, including XMR

Download ESXI[VORTEX]

Note:

Limited copies are provided for now, price change and/or suspension of sells are possible.

Todo:

  • Adding multithreading functionality.
  • Writting a complete analyze.
  • Check if target is vulnerable and save it to file.

My Other Works:

if your interrested in my other works here is the latest which I still consider selling
full configuration and after purchase service is offered with this exploit.

Magento --> CVE-2024-34102

Download Tool