How can an attacker with local administrator privileges on vCenter gain access to the VCSA management panel?
An attacker extracts the IdP certificate from the /storage/db/vmware-vmdir/data.mdb file, then creates a SAML request for an administrator user. Using the vCenter server to authenticate, they obtain a valid JSESSIONID cookie, which allows them to log into the VCSA management panel as an administrator. --- **Related reading:** - [vSphere Development Guide 6 - vCenter SAML Certificates](/news/vsphere-development-guide-6-vcenter-saml-certificates) — original article - [Covenant Utilization Analysis](/news/covenant-utilization-analysis) - [ADAudit Plus Exploitation Analysis — Data Encryption Analysis](/news/adaudit-plus-exploitation-analysis-data-encryption-analysis) - [Domain Penetration - Executing Programs on Remote Systems Using DCOM](/news/domain-penetration-executing-programs-on-remote-systems-using-dcom)
Related article:
vSphere Development Guide 6 - vCenter SAML Certificates