vCenter has a long record of critical, often pre-authentication, remote code execution in its bundled services: plugins and the update manager exposed on 443, Java deserialization endpoints, and server-side request forgery that reaches internal admin interfaces. These land as root on the appliance, which is total control of the virtual estate.
Recurring vCenter management flaw classes:
- Unauthenticated file upload / path traversal in bundled plugins
- Java deserialization in exposed endpoints
- SSRF reaching internal-only admin services
- Logging-library expression injection in exposed inputs
Exploitation notes#
- These are pre-auth in many cases, so a reachable vCenter on
443is exploitable without any credential; the payoff is root on the appliance. - Root on the appliance leads straight to SSO and token abuse and the per-host
vpxusercredentials. - Internet-exposed or flat-network vCenters are heavily targeted; the same flaws drive mass ESXi compromise.