Google’s osconfig agent – local privilege escalation

Posted by Imre Rad on Sep 22

Osconfig is a beta service by Google, a poll based “desired state
configuration” solution: “You can use the OS configuration management
service to deploy, query, and maintain consistent configurations
(desired state and software) for your VM instance (VM).”
VMs on the Compute Engine have a privileged agent process called
“google_osconfig_agent” running by default.

The agent was vulnerable to local privilege…

