Research reveals Azure IMDS allows single-command subscription takeover

cyb3rops · x · 2026-08-31

A security researcher disclosed abuse of the Azure Instance Metadata Service (IMDS), showing that a single curl command on an exposed Azure VM can yield Managed Identity tokens, leading to full subscription compromise. The paper documents the entire kill chain, including resource enumeration, Key Vault draining, and rapid privilege escalation, highlighting common misconfigurations in RBAC and the blast radius of IMDS tokens.

Original post →

More from Safety

Safety channel →