
MAL-014: Authenticated Arbitrary File Read in VMware vCenter Server
The “com.vmware.appliance.version1.system.update.set” API component is vulnerable to a flag injection attack that can be leveraged with the “com.vmware.showlog” plugin in order to read arbitrary files as the “root” user on the target system.
Note: This vulnerability requires both admin access to the vCenter SSH shell as well as access to the filesystem as a low privilege user in order to create symlink files and/or folders.
This vulnerability was found in collaboration with Alexandru Bogdan.
This vulnerability requires:
More details and the exploitation process can be found in this PDF.