Demystifying the Access Control Mechanism of ESXi VMKernel
Yue Liu, Zexiang Zhang, Jiaxun Zhu, Hao Zheng, Jiaqing Huang, Wenbo Shen, Gaoning Pan, Yuliang Lu, Min Zhang, Zulie Pan, Guang Cheng
Abstract
VMware ESXi is a widely deployed enterprise-grade Type-1 hypervisor that serves as the foundation for modern cloud infrastructure. To reinforce privilege isolation, ESXi introduced a mandatory access control mechanism in VMKernel. However, due to VMKernel's proprietary and closed-source nature, its internal access control architecture remains largely opaque and underexplored. Prior research has focused primarily on virtual device vulnerabilities and virtual machine escape, leaving the internal access control mechanisms and privilege model of VMKernel largely unexamined. To address this gap, we conduct the first comprehensive security analysis of VMKernel's access control mechanism. We develop a domain-control structure oriented analysis method to reconstruct key internal permission logic, and design a structureaware debugging framework to support fine-grained runtime validation. Using this framework, we uncover several critical design flaws, including writable and unprotected in-memory control structures and exploitable developer-reserved syscall interfaces. We demonstrate three practical attack scenarios that abuse these flaws to bypass sandbox restrictions, escalate privileges, and gain persistent access. In total, we discovered and reported 14 vulnerabilities to VMware, all of which have been confirmed and fixed, with a total of $42,000 in bug bounties awarded. I. INTRODUCTION VMware ESXi is a leading enterprise-grade Type-1 virtualization platform, widely deployed in private clouds, enterprise data centers, and other mission-critical environments. It is built on a bare-metal architecture that delivers high performance, strong isolation, and fine-grained resource scheduling, enabling large-scale virtual machine(VM) deployments and high-availability cluster management. Within the bare-metal hypervisor segment, ESXi holds over 45% of the global market share [1], establishing itself as a cornerstone of modern cloud infrastructure and playing a critical role in business continuity, security, and elastic resource management.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d43b3da3-5ede-4a41-8a1e-4e9d102ea4e5Builds on14
- MoonShine: Optimizing OS Fuzzer Seed Selection with Trace DistillationShankara Pailoor, Andrew Aday, Suman JanaUSENIX Security 2018 · 180 citations
- V-Shuttle: Scalable and Semantics-Aware Hypervisor Virtual Device FuzzingGaoning Pan, Xingwei Lin, Xuhong Zhang, Yongkang Jia et al.CCS 2021 · 23 citations
- HYPERPILL: Fuzzing for Hypervisor-bugs by leveraging the Hardware Virtualization InterfaceAlexander Bulekov, Qiang Liu, Manuel Egele, Mathias PayerUSENIX Security 2024 · 15 citations
- HyperFuzzer: An Efficient Hybrid Fuzzer for Virtual CPUsXinyang Ge, Ben Niu, Robert Brotzman, Yaohui Chen et al.CCS 2021 · 9 citations
- Insvdf: Interface-State-Aware Virtual Device FuzzingZexiang Zhang, Gaoning Pan, Ruipeng Wang, Yiming Tao et al.ICSE 2025 · 2 citations
Related papers
- Deconstructing XenLe Shi, Yuming Wu, Yubin Xia, Nathan Dautenhahn et al.NDSS 2017 · 54 citations
- Hardening Hypervisors with OmbroEthan Johnson, Colin Pronovost, John CriswellUSENIX ATC 2022
- 00SEVen - Re-enabling Virtual Machine Forensics: Introspecting Confidential VMs Using Privileged in-VM AgentsFabian Schwarz, Christian RossowUSENIX Security 2024 · 10 citations
- Veil: A Protected Services Framework for Confidential Virtual MachinesAdil Ahmad, Botong Ou, Congyu Liu, Xiaokuan Zhang et al.ASPLOS 2023 · 12 citations
- GadgetMeter: Quantitatively and Accurately Gauging the Exploitability of Speculative GadgetsQi Ling, Yujun Liang, Yi Ren, Baris Kasikci et al.NDSS 2025
