vmware-vcenter-attack

Assess internet-exposed VMware vCenter appliances for vulnerabilities and misconfigurations.

13|2|Updated Jun 1, 2026
One-click install
npx skills add https://github.com/pdparchitect/rook --skill vmware-vcenter-attack-pdparchitect
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vmware-vcenter-attack
Source: https://github.com/pdparchitect/rook/tree/main/skills/vmware-vcenter-attack
Command: npx skills add https://github.com/pdparchitect/rook --skill vmware-vcenter-attack-pdparchitect

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill addresses the critical need to identify and assess the security posture of internet-exposed VMware vCenter, Workspace ONE, and Aria instances, which are frequently targeted by threat actors due to their high-impact, pre-authentication remote code execution vulnerabilities.

Core Features & Use Cases

  • Version Fingerprinting: Automatically detects patch levels and product versions via public endpoints and TLS metadata to determine CVE applicability.
  • CVE Matrix Analysis: Maps discovered versions against a comprehensive database of critical, externally-exploitable vulnerabilities like CVE-2021-21972 and CVE-2023-34048.
  • Configuration Auditing: Identifies insecure defaults, exposed Managed Object Browsers (MOB), and SSO configuration disclosures that could lead to full virtualization-plane compromise.

Quick Start

Use the vmware-vcenter-attack skill to audit the target vcenter.target.com for exposed management interfaces and missing security patches.

Frequently Asked Questions about vmware-vcenter-attack

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit VMware vCenter for exposed management interfaces and missing security patches?

Auditing VMware vCenter involves performing security reconnaissance to fingerprint versions, analyze CVE applicability against known vulnerabilities, and discover misconfigurations on exposed management appliances. This identifies critical virtualization-plane risks.

What CVEs are checked during a VMware vCenter vulnerability assessment?

A VMware vCenter vulnerability assessment maps discovered product versions against critical, externally-exploitable vulnerabilities like CVE-2021-21972 and CVE-2023-34048 to determine patch levels and CVE applicability.

How do I detect exposed Managed Object Browsers and SSO configuration disclosures on VMware appliances?

Configuration auditing detects exposed Managed Object Browsers (MOB) and SSO configuration disclosures on VMware appliances by identifying insecure defaults that could lead to full virtualization-plane compromise.

Does VMware vCenter reconnaissance require internal network access to management ports?

VMware vCenter reconnaissance requires network access to management ports to evaluate attack surfaces, but it strictly adheres to external-only engagement boundaries for internet-exposed instances.

Can I fingerprint VMware Workspace ONE and Aria instances using the same security posture audit?

Security posture auditing fingerprints versions across VMware Workspace ONE and Aria instances via public endpoints and TLS metadata to assess patch levels and determine CVE applicability.

What are the limitations of external-only VMware vCenter security reconnaissance?

External-only VMware vCenter reconnaissance is limited to internet-exposed attack surfaces, preventing internal configuration deep-dives while focusing on version fingerprinting, CVE matrix analysis, and misconfiguration discovery.