A KVM host is a Linux machine running qemu-kvm processes, managed through libvirt (libvirtd) and its socket. Control of the host, or of the libvirt socket, is control of every VM: virsh lists, starts, stops, and consoles them, and the disk images are on the host filesystem. Membership in the libvirt group or access to the socket is enough.
virsh list --all # every guest
virsh dumpxml <vm> # config, disk paths, devices
virsh console <vm> # guest console
ls /var/lib/libvirt/images/ # qcow2/raw disks
# The socket is the control boundary
ls -l /var/run/libvirt/libvirt-sock
Exploitation notes#
- Access to
/var/run/libvirt/libvirt-sock(often via thelibvirtgroup) is full VM control without root on the host. virshgives console access and lets you edit a VM to attach a disk or change boot, and the images are directly readable for Disk and snapshot theft.- Remote libvirt (
qemu+tcp/qemu+ssh) with weak auth is a network-reachable control path to the same power.