Escalating privileges to read secrets with Azure Key Vault access policies
ID: 8bcd38f1-b654-5fbc-ba74-8a0547db278f
STIX ID: report--8bcd38f1-b654-5fbc-ba74-8a0547db278f
Feed Name: Datadog Security Labs
Datadog describes a privilege-escalation path in Azure Key Vault: when a vault uses access policies, a user with the Key Vault Contributor role (or Microsoft.KeyVault/vaults/write) can modify access policies to grant themselves data-plane access and read all secrets, keys, and certificates. Microsoft classified this as “not a vulnerability” and updated documentation to warn customers, recommending the RBAC permissions model, auditing and limiting roles with vaults/write, reviewing/removing unauthorized access policies, and rotating potentially exposed secrets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
