Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

IMDS impersonation

0
Low
Vulnerability
Published: 06/05/2026 (06/05/2026, 19:19:25 UTC)
Source: AWS Security Bulletins

Description

Bulletin ID: AWS-2025-021 Scope: AWS Content Type: Important (requires attention) Publication Date: 2025/10/07 01:30 PM PDT Description: AWS is aware of a potential Instance Metadata Service (IMDS) impersonation issue that would lead to customers interacting with unexpected AWS accounts. IMDS, when running on an EC2 instance, runs on a loopback network interface and vends Instance Metadata Credentials, which customers use to interact with AWS Services. These network calls never leave the EC2 instance, and customers can trust that the IMDS network interface is within the AWS data perimeter. When using AWS tools (like the AWS CLI/SDK or SSM Agent) from non-EC2 compute nodes, there is a potential for a third party-controlled IMDS to serve unexpected AWS credentials. This requires the compute node to be running on a network where the third party has a privileged network position. AWS recommends that when using AWS Tools outside of the AWS data perimeter, customers follow the installation and configuration guides (AWS CLI/SDK or SSM Agent) to ensure this issue is mitigated. We also recommend that you monitor for IMDS endpoints that may be running in your on-prem environment to proactively prevent such impersonation issues from a third party. Affected versions: IMDSv1 and IMDSv2

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/05/2026, 19:31:16 UTC

Technical Analysis

The IMDS impersonation issue involves the risk that AWS tools running outside EC2 instances on networks controlled or influenced by a third party may receive credentials from a maliciously impersonated IMDS endpoint. Normally, IMDS operates on a loopback interface within EC2 instances, ensuring metadata and credentials are securely delivered within the AWS data perimeter. This vulnerability arises when AWS CLI/SDK or SSM Agent are used on non-EC2 compute nodes in environments where an attacker can position themselves to respond to IMDS requests, potentially causing the client to interact with unexpected AWS accounts. The issue affects both IMDSv1 and IMDSv2. AWS advises customers to adhere strictly to installation and configuration best practices for these tools outside AWS environments and to monitor network traffic for IMDS-related endpoints and metadata requests to detect anomalous activity.

Potential Impact

If exploited, this issue could lead to AWS tools outside the AWS data perimeter receiving credentials from unauthorized IMDS endpoints controlled by third parties. This may cause customers to unknowingly interact with unexpected AWS accounts, potentially leading to unauthorized access or data exposure. However, exploitation requires the attacker to have a privileged network position on the same network as the affected compute node. The severity is assessed as low by AWS, reflecting limited risk under typical deployment scenarios.

Mitigation Recommendations

AWS recommends that customers using AWS CLI, SDK, or SSM Agent outside the AWS data perimeter strictly follow the official installation and configuration guides to mitigate this issue. Additionally, organizations should monitor their on-premises networks for unexpected IMDS traffic, including connections to the IPv4 link-local endpoint 169.254.169.254, the IPv6 endpoint fd00:ec2::254, HTTP requests to AWS metadata paths (/latest/meta-data, /latest/api/token), and the presence of AWS metadata headers such as X-aws-ec2-metadata-token. Detection rules, such as those provided in SIGMA format, can be deployed in SIEM systems to identify potential impersonation attempts. No official patch is indicated; mitigation relies on proper configuration and proactive monitoring.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://aws.amazon.com/security/security-bulletins/rss/aws-2025-021/","fetched":true,"fetchedAt":"2026-05-26T20:30:24.506Z","wordCount":534}

Threat ID: 6a1602eae29bf47b505d9f9e

Added to database: 05/26/2026, 20:30:34 UTC

Last enriched: 06/05/2026, 19:31:16 UTC

Last updated: 07/30/2026, 17:38:05 UTC

Views: 60

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses