NetSPI Details Azure Privilege-Escalation Risks and a Fixed Built-In Role

· Original article ↗

Summary

NetSPI explains how Azure RBAC permissions and ABAC conditions can create privilege-escalation paths, and reports that Microsoft removed role-assignment permissions from the Anyscale Platform Administrator built-in role.

Key points

  • NetSPI’s permission-mapping research found that the Anyscale Platform Administrator built-in role allowed arbitrary role assignments and escalation to Owner because it lacked ABAC constraints.
  • Microsoft removed the role’s role-assignment write and delete permissions after the issue was reported to MSRC.
  • The researchers describe how a custom role containing role-assignment permissions could bypass a recommended ABAC condition on Owner or User Access Administrator; MSRC marked this behavior as by design.
  • The article explains how Azure’s RBAC and ABAC permissions, conditions, scopes, and data-plane access affect privilege-escalation analysis.
  • NetSPI used the ARM Role Definitions List API’s hasAllPermissions filter to map risky permissions to built-in and custom roles.
  • The research notes that permissions such as Storage Account key listing can grant data access, even when included in roles intended for other services.
  • The authors recommend reviewing all roles, applying least privilege, and assigning roles at the narrowest practical scope.

Article Details

Attack Vectors
  • A principal with a Portal-recommended ABAC condition on an Owner or User Access Administrator assignment could create a custom role containing Microsoft.Authorization/roleAssignments/write, then assign that role to themselves or another principal. The resulting unconstrained role would bypass the assignment's condition; MSRC closed the report as by design.
  • The Anyscale Platform Administrator Role previously included unconstrained Microsoft.Authorization/roleAssignments/write and /delete permissions. Researchers reported that a principal assigned the role could grant Owner access. Microsoft subsequently removed those permissions.
  • Microsoft.Storage/storageAccounts/listkeys/action can expose Storage Account Shared Access Keys, which provide data-plane access. Assignment scope determines how many Storage Accounts a principal could access.
  • The article identifies VM run-command access, assignment of User Assigned Managed Identities, and access to supporting-service secrets as categories of potential privilege-escalation paths.
Defensive Notes
  • Review ABAC conditions alongside RBAC permissions when assessing a role's effective access; a condition on role-assignment writes does not necessarily constrain other privileged permissions.
  • Review built-in and custom roles for unexpected permissions before assignment, apply least privilege, and assign roles at the narrowest practical scope.
  • Logically segment workloads, including placing critical identity resources in a dedicated Subscription where appropriate.

MITRE ATT&CK

People

Vendors

Products

Tools

Related Articles