---
title: >-
  Vulnerable compute instance is publicly reachable with a service account that
  can escalate to administrative permissions
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > Vulnerable compute instance is publicly
  reachable with a service account that can escalate to administrative
  permissions
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Vulnerable compute instance is publicly reachable with a service account that can escalate to administrative permissions

## Description{% #description %}

A publicly accessible Compute Engine instance has one or more vulnerabilities and assumes a service account that can escalate its privileges to another service account with administrator access. An attacker who exploits a vulnerability to compromise the instance from the internet can use the attached service account's credentials to escalate privileges and gain administrative control over the GCP project.

## Remediation{% #remediation %}

1. Review any associated vulnerability references or advisories, and apply the appropriate patch. If no patch is available, apply compensating controls such as disabling or removing the vulnerable component.
1. Assess whether this instance needs to be accessible from the internet. If not, restrict access by updating firewall rules to only allow traffic from trusted sources. See [VPC firewall rules](https://cloud.google.com/firewall/docs/firewalls) for guidance.
1. Review and restrict the service account's IAM permissions to remove privilege-escalation paths (e.g. `roles/iam.serviceAccountTokenCreator`, `iam.serviceAccounts.actAs`, and related bindings). See [Understanding roles](https://cloud.google.com/iam/docs/understanding-roles) for applying least privilege.
