vCenter Server manages many ESXi hosts, so compromising it is compromising the whole virtual estate. It is a web and API appliance built on a photon-OS base with a single sign-on (SSO) system, an identity store (vmdir), and a history of critical management-service flaws. Control of vCenter yields the vpxuser credential for every host and the ability to run on any VM.
Subtopics#
- Enumeration: mapping the inventory and identities.
- SSO and token abuse: forging administrator access.
- Known management exploits: critical service vulnerabilities.