What problem does it solve?
This skill addresses the high risk of unpatched, internet-exposed VMware vCenter, vSphere, Workspace ONE, and Aria management infrastructure, a common high-value target in external penetration tests and red team engagements that often runs outdated versions with critical pre-authentication remote code execution vulnerabilities enabling full takeover of the virtualization plane and all hosted workloads.
Core Features & Use Cases
- CVE Exploitation Matrix: Covers 10+ high-impact pre-auth CVEs including CVE-2021-21972, CVE-2021-21985, CVE-2022-22954, CVE-2023-34048, and CVE-2024-37085, with step-by-step safe probes, validation logic, and explicit sign-off requirements for exploitation steps.
- Recon & Fingerprinting: Identifies VMware product banners, exact version build numbers, and exposed management endpoints (Managed Object Browser, SSO, vSphere REST API) to confirm target scope and CVE applicability.
- Use Case: For example, during an external engagement, if recon reveals a vCenter Server banner on port 443, use this skill to fingerprint the version, probe for unpatched critical CVEs, and gain full control of the virtualization plane including all hosted VMs, datastores, and ESXi hosts.
Quick Start
Use the vmware-vcenter-attack skill to assess the internet-exposed vCenter instance at target.example.com for unpatched critical CVEs and potential full virtualization plane takeover, following all external-only scope and explicit exploitation sign-off rules.