Home / exploitsPDF  

VMware vCenter Server Virtual SAN Health Check Remote Code Execution

Posted on 13 July 2021

This Metasploit module exploits Java unsafe reflection and SSRF in the VMware vCenter Server Virtual SAN Health Check plugin's ProxygenController class to execute code as the vsphere-ui user. See the vendor advisory for affected and patched versions. Tested against VMware vCenter Server 6.7 Update 3m (Linux appliance

 

TOP