logo

Escalating privileges to read secrets with Azure Key Vault access policies

ID: 8bcd38f1-b654-5fbc-ba74-8a0547db278f

STIX ID: report--8bcd38f1-b654-5fbc-ba74-8a0547db278f

Feed Name: Datadog Security Labs

Date Published: 2024-12-16

Date Updated: 2026-04-27

...
...

Datadog describes a privilege-escalation path in Azure Key Vault: when a vault uses access policies, a user with the Key Vault Contributor role (or Microsoft.KeyVault/vaults/write) can modify access policies to grant themselves data-plane access and read all secrets, keys, and certificates. Microsoft classified this as “not a vulnerability” and updated documentation to warn customers, recommending the RBAC permissions model, auditing and limiting roles with vaults/write, reviewing/removing unauthorized access policies, and rotating potentially exposed secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.