AgentCorruption Flaw Could Expose AWS Bedrock AgentCore Environments to Takeover

· Original article ↗

Summary

Researchers found that a prompt to a public-facing Bedrock AgentCore agent could expose instance credentials and enable access to other agents and secrets in an AWS region. AWS updated IMDS settings and default permissions; researchers reported no known exploitation.

Key points

  • Zenity researchers found AgentCore agents could access Instance Metadata Services (IMDS), which can provide temporary credentials and instance information.
  • A single prompt to a public-facing agent with HTTP request capability could trigger an IMDS request and compromise that agent.
  • Researchers said AgentCore's default role had broad regional permissions, enabling access to other agents, sessions, and AWS Secrets Manager secrets.
  • The researchers also reported the potential for memory-poisoning attacks against agents.
  • AWS updated AgentCore in February so newly deployed agents use authenticated IMDSv2 and restricted the default role's permissions.
  • Zenity reported the issues to AWS beginning in December; researchers said they had no evidence of exploitation before the fixes.

Article Details

Vulnerability Types
  • Insufficient network isolation allowing agents to access the Instance Metadata Service
  • Overly permissive default role
Exploitation Status
not_reported
Exploit Availability
unknown
Patch Status
available
Workarounds
  • Limit agent privileges to those required for the agent's specific role.

MITRE ATT&CK

People

Vendors

Products

Industries

Related Articles