Instance metadata

The Azure Instance Metadata Service (IMDS) answers on the link-local 169.254.169.254 to any process on a VM, and its token endpoint hands out an access token for the resource's managed identity. Any foothold on a managed-identity-bearing resource, direct code execution or a server-side request forgery, turns into a token for whatever that identity can reach.

What folds in here#

  • Managed identity token: requesting and replaying the token from the IMDS endpoint on the host.
  • SSRF to IMDS: reaching the same endpoint through a vulnerable application.

Unlike AWS, Azure IMDS requires a Metadata: true request header and takes a resource parameter naming the audience (ARM, Microsoft Graph, Key Vault, storage), so a token is scoped to one audience at a time.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more