Known escape exploits

Public VMware escapes concentrate in a handful of emulated devices. The SVGA 3D graphics adapter has produced repeated host code execution and is the classic Pwn2Own target. USB controller emulation (UHCI, EHCI, XHCI) and the virtual NICs (vmxnet3, e1000) have also yielded escapes. The same vmware-vmx device code is shared with Workstation and Fusion, so many escapes affect all three.

text
Recurring VMware escape surfaces:
- SVGA II / 3D graphics acceleration (the primary target)
- USB controllers: UHCI / EHCI / XHCI
- Virtual NICs: vmxnet3, e1000
- The backdoor RPC and VMCI channels

Exploitation notes#

  • Reachability is configuration-dependent: 3D acceleration and specific USB controllers must be present on the guest; hardened VMs disable them.
  • Escapes land in the vmware-vmx process first, then escalate to the host; public chains pair a device bug with a host privilege escalation.
  • The shared device code means a Workstation or Fusion finding often ports to ESXi and the reverse; see Workstation and Fusion.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more