Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
MAL-014 — MAL-014: Authenticated Arbitrary File Read in VMware vCenter Server | Kitploit
Tools/GitHubGitHub/mbadanoiu/mal-014
Vulnerability AnalysisExploitationData ExfiltrationPost-ExploitationPenetration Testing
GitHubmbadanoiu/mal-014

MAL-014

MAL-014: Authenticated Arbitrary File Read in VMware vCenter Server

View Repository
41 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

MAL-014: Authenticated Arbitrary File Read in VMware vCenter Server

The “com.vmware.appliance.version1.system.update.set” API component is vulnerable to a flag injection attack that can be leveraged with the “com.vmware.showlog” plugin in order to read arbitrary files as the “root” user on the target system.

Note: This vulnerability requires both admin access to the vCenter SSH shell as well as access to the filesystem as a low privilege user in order to create symlink files and/or folders.

Collaboration:

This vulnerability was found in collaboration with Alexandru Bogdan.

Requirements:

This vulnerability requires:

  • Valid credentials for user with "admin" role on the restricted vCenter SSH shell
  • Access to the file system in order to create symlinks

Proof Of Concept:

More details and the exploitation process can be found in this PDF.

Timeline:

  • Vulnerability was reported to [email protected] (now [email protected]) on 12-Apr-2023
  • It was determined that the vulnerability could not be replicated in latest vCenter version at the time (8.0 U1)
  • Publicly disclosed the vulnerability on 21-Apr-2025
Download Tool