high

Escalating from Reader to Contributor in Azure API Management

Published Fri, Sep 13th, 2024

Platforms

azure

Summary

A vulnerability in Azure API Management allowed users with Reader access to escalate privileges to Contributor level by accessing admin user keys via the ARM API. This permitted full management capabilities through the Direct Management API, including reading secrets and modifying configurations.

Affected Services

API Management

Remediation

Enable "Disable old API versions" setting for Azure API Management instances.

Tracked CVEs

No tracked CVEs

References

Contributed by https://github.com/korniko98

Entry Status

Stub (AI-Generated)

Disclosure Date

Tue, Apr 30th, 2024

Exploitability Period

Until 2024/06/04

Known ITW Exploitation

-

Detection Methods

Monitor for unexpected privilege escalation or configuration changes in Azure API Management resources.

Piercing Index Rating

-

Discovered by

Christian Håland, Binary Security AS