Shared folder and drag-drop abuse

VMware Tools adds host integration: Shared Folders (HGFS) expose host directories to the guest, and drag-and-drop and clipboard sharing move data across the boundary. When enabled, Shared Folders is a direct host file read and write primitive from the guest, and the drag-and-drop and HGFS request handlers have themselves been guest-to-host code-execution bugs.

bash
# Inside a Linux guest with Shared Folders enabled
ls /mnt/hgfs/                                   # host directories exposed to the guest
vmware-hgfsclient                               # list configured shares
# Writing into a shared folder reaches the host filesystem directly

Exploitation notes#

  • Shared Folders is often enabled in analysis VMs for convenience; it turns a guest foothold into host file access with no exploit.
  • The HGFS and drag-and-drop request parsers have produced memory-corruption escapes in their own right, reachable only when the feature is on.
  • Disabling Shared Folders and drag-and-drop removes this surface, so its presence is the precondition to check first.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more