Compute Engine

A Compute Engine VM binds two things an attacker wants: a way to run code (through instance metadata, which the guest trusts for startup scripts and SSH keys) and an identity (the attached service account, whose token the metadata server dispenses). Holding compute.instances.setMetadata on an instance is effectively code execution on it; reaching the metadata server from a shell on it is its service account.

What folds in here#

  • Metadata and SSH: writing a startup script or SSH key to land a shell, and reading the metadata server on-host.
  • Service account scope: using the instance's attached service account and OAuth scopes to call Google APIs.

Creating a new VM with a privileged service account attached is the actAs compute-instance escalation; these pages cover existing instances.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more