Azure Privilege Escalation Using Managed Identities
netspi.com | 漏洞 | #cloud | #cloud-security | #privilege-escalation | #azure | #pentest | #managed-identity
摘要
Azure 托管标识滥用研究:VM 的托管标识若被授予 Contributor/Owner 等过高权限,任何能在该 VM 执行命令的人(RDP 登录、应用漏洞、VM Contributor 角色等)都可请求其令牌并以此身份操作订阅,实现提权;附 az vm list 枚举一行命令。
- 发布时间
- 收录时间
Skip to content