Publicly accessible Azure VM with high/critical vulnerabilities has a managed identity with administrator-equivalent RBAC rights

Description

A publicly accessible Azure VM has one or more open high or critical severity vulnerabilities and a managed identity with administrator-equivalent Azure RBAC rights at the tenant root, a management group, or a subscription. If the VM is compromised, an attacker could use the managed identity to control resources and security settings within that scope.

Remediation

  1. Apply security updates to remediate the vulnerability and restrict public network access to the virtual machine. See Guest updates and host maintenance and Azure network security groups.
  2. Remove administrator-equivalent role assignments from the managed identity and grant only the permissions required by the workload. See Remove Azure role assignments.