ESXi is a thin, hardened hypervisor managed through a host client, SSH, and the vSphere API. Each VM is served by a vmx user-space process that emulates its devices, which is the guest-to-host escape surface, while the datastore holds every VM's VMDK disk. ESXi hosts are now a favored target for mass VM encryption, so access patterns and offline disk theft matter as much as escapes.
Subtopics#
- Host access and shell: reaching the ESXi shell and API.
- Guest to host escape: breaking out through VMX device emulation.
- Datastore and VMDK theft: stealing guest disks offline.
- Known escape exploits: named ESXi breakouts.