Known escape exploits

Proxmox inherits most of its escape surface from the components it builds on. VM breakouts are the QEMU and KVM escapes (the VENOM class, virtio, and device-model bugs). Container breakouts are the LXC and Linux container-escape primitives. On top, the Proxmox web and API stack has its own authentication and web vulnerabilities that grant node or cluster control without any guest escape.

text
Proxmox-relevant escape classes:
- QEMU/KVM device-model escapes (VMs)
- LXC / Linux container escapes (containers)
- Proxmox web and API auth and injection flaws (control plane)

Exploitation notes#

  • For VMs, use KVM and QEMU known escape exploits; for containers, the Container escape primitives.
  • Proxmox-specific flaws target the 8006 web stack and the API authentication, often yielding node root directly.
  • The node is a cluster member, so any node-level code execution is a step toward whole-cluster control.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more