Publicly accessible Azure VM with high/critical vulnerabilities has a managed identity that can read data from crown jewel storage

Description

A publicly accessible Azure VM has one or more open high or critical severity vulnerabilities and a managed identity that can read data from a crown jewel blob container. If the VM is compromised, an attacker could use the managed identity to read or exfiltrate business-critical data.

Remediation

  1. Apply security updates to remediate the vulnerability and restrict public network access to the virtual machine. See Guest updates and host maintenance and Azure network security groups.
  2. Remove unnecessary Blob data read permissions from the managed identity. See Remove Azure role assignments.