The Guest Who Could: Exploiting LPE in VMWare Tools
swarm.ptsecurity.com | research | #vulnerability-research | #windows | #saml | #vmware-tools | #vgauth | #local-privilege-escalation
Summary
PT SWARM details LPE flaws in VMware Tools' Windows VGAuth service (12.5.0) — a SYSTEM-level component for alias store, ticket and SAML auth on guest VMs, an overlooked guest-only attack surface.
- Published
- Collected
Skip to content