Proxmox VE is Debian plus KVM and LXC with a clustered web and REST management layer. It has become a leading destination for teams leaving ESXi, so it is an increasingly common target. Offensively, it is a Debian host (root there owns everything), a web and API control plane with its own ticket and token authentication, QEMU/KVM-backed guests with the usual escape surface, and virtual disks and backups at rest.
Subtopics#
- Host access and shell: reaching the node.
- Guest to host escape: breaking out through QEMU/KVM.
- Management plane: the cluster API and authentication.
- Disk and backup theft: disks, snapshots, and vzdump backups.
- Known escape exploits: named Proxmox and QEMU breakouts.