AWS EC2 Metadata Service v1 Abuse Flaw

3D IM 20 Reputation points
2026-10-06T19:25:53.03+00:00

Security audit flags EC2 instances allowing IMDSv1 access, posing SSRF vulnerabilities. How do we enforce IMDSv2 mandatory tokens across existing instances via AWS CLI?

Windows for business | Windows 365 Business
0 comments No comments

1 answer

Sort by: Newest
  1. Chance Maurice Niyonzima 255 Reputation points Independent Advisor
    2026-10-06T20:07:24.0066667+00:00

     Hello Admin,

    Thank you for posting your question on Microsoft Windows Forum!

    Yes, AWS provides a supported way to enforce IMDSv2 and disable IMDSv1 access on existing EC2 instances using the AWS CLI. AWS documents that you can modify the instance metadata options of a running or stopped instance using the modify-instance-metadata-options command.

    Before Enforcing IMDSv2

    AWS recommends first verifying that your applications are no longer making IMDSv1 requests. The MetadataNoToken CloudWatch metric can be used to identify IMDSv1 usage. AWS advises requiring IMDSv2 only after this metric shows zero IMDSv1 calls.

    Enforce IMDSv2 on an Existing Instance

    Using PowerShell:

    aws ec2 modify-instance-metadata-options </span>

        --instance-id i-xxxxxxxxxxxxxxxxx </span>

        --http-tokens required

    When http-tokens is set to:

    required

    IMDSv2 becomes mandatory and IMDSv1 requests are no longer allowed.

    Verify the Setting

    Using PowerShell:

    aws ec2 describe-instances </span>

        --instance-ids i-xxxxxxxxxxxxxxxxx </span>

        --query "Reservations[].Instances[].MetadataOptions"

    AWS notes that when modifying a running instance, the change may initially show as:

    pending

    and later transition to:

    applied

    once the modification completes.

    Apply to Multiple Instances

    For multiple EC2 instances, you can apply the change in a loop:

    Using PowerShell:

    for id in $(aws ec2 describe-instances </span>

      --query "Reservations[].Instances[].InstanceId" </span>

      --output text)

    do

      aws ec2 modify-instance-metadata-options </span>

        --instance-id $id </span>

        --http-tokens required

    done

    Additional Recommendation

    If this is a compliance requirement identified during a security audit, you may also want to prevent future instances from being launched with IMDSv1 enabled by reviewing your account-level EC2 metadata settings and deployment templates. AWS also supports IAM policies to control who can modify instance metadata options.

    For official AWS guidance, please review:

    I hope this answer has brought you useful information. If so, please click on "Accept Answer" and consider upvoting it. Doing so helps other community members identify useful solutions to similar issues

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.