Misconfiguration Spotlight: Securing the EC2 Instance Metadata Service
ID: 1ff0b321-f2ad-5911-b7e0-88136b65801c
STIX ID: report--1ff0b321-f2ad-5911-b7e0-88136b65801c
Feed Name: Datadog Security Labs
Threat Score
This Misconfiguration Spotlight explains that EC2 Instance Metadata Service version 1 (IMDSv1) is vulnerable to credential theft via SSRF, details how IMDSv2 mitigates the risk, cites real-world exploitation (CVE-2021-21311 referenced by Mandiant), and provides concrete mitigations—SCP policies to require IMDSv2, AMI configuration guidance, and detection/testing recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
