medium

Azure privilege escalation via Log Analytics role

Published Mon, Sep 13th, 2021

Platforms

azure

Summary

Azure AD users could escalate their privileges using the Log Analytics Contributor role to reach the full Subscription Contributor role.

Affected Services

Log Analytics

Remediation

None required

Tracked CVEs

No tracked CVEs

References

Contributed by https://github.com/0xdabbad00

Entry Status

Finalized

Disclosure Date

Thu, Oct 15th, 2020

Exploitability Period

-

Known ITW Exploitation

-

Detection Methods

None

Piercing Index Rating

-

Discovered by

Karl Fosaaen, NetSPI