HomeSecurityHackers exploit IMDS service to access cloud environments

Hackers exploit IMDS service to access cloud environments

Malicious actors exploit the Instance Metadata Service (IMDS), a key component designed to securely provide temporary credentials to compute instances, to infiltrate and navigate cloud infrastructures.

See also: Drift hacks: 1.5 billion Salesforce files in the hands of ShinyHunters

IMDS

By forcing unsuspecting applications to query IMDS endpoints, attackers collect short-lived tokens, enabling credential theft, lateral movement, and privilege escalation within victims' environments.

Wiz reports that the Example Metadata Service runs at the heart of AWS, Azure , and GCP, exposing critical data and IAM credentials via HTTP requests to the privileged address 169.254.169.254.

See also: Microsoft OneDrive Auto-Sync exposes data in SharePoint Online

Hackers exploit IMDS service to access cloud environments

While IMDSv2 enhances security through session-oriented token recovery, IMDSv1 remains vulnerable to Server-Side Request Forgery (SSRF). Attackers exploit SSRF weaknesses or misconfigured workloads to forge IMDS calls, stealing role-based credentials without direct control of the host.

By establishing a base of legitimate clients, such as AWS SDKs, EC2 agents, and nm-cloud-setup, researchers isolate processes that rarely access IMDS. Filtering for sensitive metadata paths (for example, /latest/meta-data/iam/security-credentials/ and /computeMetadata/v1/instance/service-accounts/) and prioritizing examples with online exposure reveals insidious identification and extraction attempts.

See also: Adobe Commerce bug allows account takeover

Hackers exploit IMDS service to access cloud environments

Two real-world findings highlight the power of this tactic. In the first case, a zero-day SSRF in pandoc (CVE-2025-51591) allowed malicious HTML tags

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS