Home / Series / Chaos Communication Congress / Aired Order / Season 36 / Episode 33

The Great Escape of ESXi

(Breaking Out of a Sandboxed Virtual Machine) VMware ESXi is an enterprise-class, bare-metal hypervisor developed by VMware for deploying and serving virtual computers. As the hypervisor of VMware vSphere, which is the world's most prevailing, state-of-the-art private-cloud software, ESXi plays a core role in the enterprise's cloud infrastructure. Bugs in ESXi could violate the security boundary between guest and host, resulting in virtual machine escape. While a few previous attempts to escape virtual machines have targeted on VMware workstation, there has been no public VMware ESXi escape until our successful demonstration at GeekPwn 2018. This is mainly due to the sandbox mechanism that ESXi has adopted, using its customized filesystem and kernel. In this talk, we will share our study on those security enhancements in ESXi, and describe how we discover and chain multiple bugs to break out of the sandboxed guest machine.

English
  • Originally Aired December 27, 2019
  • Runtime 60 minutes
  • Production Code 10505
  • Created December 27, 2019 by
    Administrator admin
  • Modified December 27, 2019 by
    Administrator admin