Known management exploits

vCenter has a long record of critical, often pre-authentication, remote code execution in its bundled services: plugins and the update manager exposed on 443, Java deserialization endpoints, and server-side request forgery that reaches internal admin interfaces. These land as root on the appliance, which is total control of the virtual estate.

text
Recurring vCenter management flaw classes:
- Unauthenticated file upload / path traversal in bundled plugins
- Java deserialization in exposed endpoints
- SSRF reaching internal-only admin services
- Logging-library expression injection in exposed inputs

Exploitation notes#

  • These are pre-auth in many cases, so a reachable vCenter on 443 is exploitable without any credential; the payoff is root on the appliance.
  • Root on the appliance leads straight to SSO and token abuse and the per-host vpxuser credentials.
  • Internet-exposed or flat-network vCenters are heavily targeted; the same flaws drive mass ESXi compromise.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more