vCenter authentication runs through SSO, which issues SAML tokens signed by the IDP's private key. An attacker who reaches the appliance filesystem or the vmdir identity store can recover that signing key and the IDP configuration, then forge a SAML assertion for the SSO administrator, authenticating as full admin without a password. This is the vSphere form of a golden SAML attack.
# On a compromised vCenter appliance: the SSO IDP signing key and vmdir data
ls /storage/db/vmware-vmdir/ # vmdir database (data.mdb)
# Extract the IDP signing certificate/key, then mint a SAML token for administrator@vsphere.local
Exploitation notes#
- Forged SSO tokens grant
administrator@vsphere.local, which is control of every managed host and VM, and they are not tied to a password, so password resets do not revoke them. - The signing key is recovered from the appliance, so this follows an initial foothold on vCenter, often via a Known management exploit.
- The vCenter database (not vmdir) holds the per-host
vpxuserpasswords vCenter uses to manage each ESXi host, so the same appliance compromise is a direct pivot to every host shell.