Demystifying the Access Control Mechanism of ESXi VMKernel
Yue Liu, Zexiang Zhang, Jiaxun Zhu, Hao Zheng, Jiaqing Huang, Wenbo Shen, Gaoning Pan, Yuliang Lu, Min Zhang, Zulie Pan, Guang Cheng
摘要
VMware ESXi is a widely deployed enterprise-grade Type-1 hypervisor that serves as the foundation for modern cloud infrastructure. To reinforce privilege isolation, ESXi introduced a mandatory access control mechanism in VMKernel. However, due to VMKernel's proprietary and closed-source nature, its internal access control architecture remains largely opaque and underexplored. Prior research has focused primarily on virtual device vulnerabilities and virtual machine escape, leaving the internal access control mechanisms and privilege model of VMKernel largely unexamined. To address this gap, we conduct the first comprehensive security analysis of VMKernel's access control mechanism. We develop a domain-control structure oriented analysis method to reconstruct key internal permission logic, and design a structureaware debugging framework to support fine-grained runtime validation. Using this framework, we uncover several critical design flaws, including writable and unprotected in-memory control structures and exploitable developer-reserved syscall interfaces. We demonstrate three practical attack scenarios that abuse these flaws to bypass sandbox restrictions, escalate privileges, and gain persistent access. In total, we discovered and reported 14 vulnerabilities to VMware, all of which have been confirmed and fixed, with a total of $42,000 in bug bounties awarded. I. INTRODUCTION VMware ESXi is a leading enterprise-grade Type-1 virtualization platform, widely deployed in private clouds, enterprise data centers, and other mission-critical environments. It is built on a bare-metal architecture that delivers high performance, strong isolation, and fine-grained resource scheduling, enabling large-scale virtual machine(VM) deployments and high-availability cluster management. Within the bare-metal hypervisor segment, ESXi holds over 45% of the global market share [1], establishing itself as a cornerstone of modern cloud infrastructure and playing a critical role in business continuity, security, and elastic resource management.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper14
- MoonShine: Optimizing OS Fuzzer Seed Selection with Trace DistillationShankara Pailoor, Andrew Aday, Suman JanaUSENIX Security 2018 · 被引用 180 次
- V-Shuttle: Scalable and Semantics-Aware Hypervisor Virtual Device FuzzingGaoning Pan, Xingwei Lin, Xuhong Zhang, Yongkang Jia 等CCS 2021 · 被引用 23 次
- HYPERPILL: Fuzzing for Hypervisor-bugs by leveraging the Hardware Virtualization InterfaceAlexander Bulekov, Qiang Liu, Manuel Egele, Mathias PayerUSENIX Security 2024 · 被引用 15 次
- HyperFuzzer: An Efficient Hybrid Fuzzer for Virtual CPUsXinyang Ge, Ben Niu, Robert Brotzman, Yaohui Chen 等CCS 2021 · 被引用 9 次
- Insvdf: Interface-State-Aware Virtual Device FuzzingZexiang Zhang, Gaoning Pan, Ruipeng Wang, Yiming Tao 等ICSE 2025 · 被引用 2 次
相关 Paper
- Deconstructing XenLe Shi, Yuming Wu, Yubin Xia, Nathan Dautenhahn 等NDSS 2017 · 被引用 54 次
- Hardening Hypervisors with OmbroEthan Johnson, Colin Pronovost, John CriswellUSENIX ATC 2022
- 00SEVen - Re-enabling Virtual Machine Forensics: Introspecting Confidential VMs Using Privileged in-VM AgentsFabian Schwarz, Christian RossowUSENIX Security 2024 · 被引用 10 次
- Veil: A Protected Services Framework for Confidential Virtual MachinesAdil Ahmad, Botong Ou, Congyu Liu, Xiaokuan Zhang 等ASPLOS 2023 · 被引用 12 次
- GadgetMeter: Quantitatively and Accurately Gauging the Exploitability of Speculative GadgetsQi Ling, Yujun Liang, Yi Ren, Baris Kasikci 等NDSS 2025
