Research has shown that Azure Storage account read and write permissions can be abused to gain broader access in cloud environments, turning what appears to be limited storage access into a path for privilege escalation and lateral movement. The findings are significant because Azure Storage accounts are widely used across organizations for blobs, files, queues, and tables, and Microsoft recommends general-purpose v2 accounts as the standard deployment model for most workloads.
Microsoft documentation underscores how central these accounts are to Azure operations, noting built-in encryption at rest, multiple redundancy options, fixed account-type choices after creation, and endpoint behaviors that administrators must manage carefully. Together, the research and platform guidance indicate that mis-scoped permissions on storage accounts can create outsized security risk, making least-privilege access, careful role assignment, and review of legacy or migrated storage configurations critical for defenders.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft states that classic Azure storage accounts were retired and advises customers to migrate legacy or GPv1 accounts to Azure Resource Manager and GPv2 where applicable.
A Security Friends' Research Blog post titled "Not the Access You Asked For: How Azure Storage Account Read/Write Permissions Can Be Abused for Privilege Escalation and Lateral Movement" was published, disclosing abuse of Azure Storage account read/write permissions for privilege escalation and lateral movement.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
learn.microsoft.com
Open sourceblog.fndsec.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.