Open cardosec

Case 38CAED · Cloud · L5 Expert

AWS IAM Privilege Escalation Paths

Practise as: Explain it · Interview

Interview questionA CI role has iam:PassRole, lambda:CreateFunction and lambda:InvokeFunction but no admin policy. Why is it admin, and how do you find such paths at scale?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. PassRole lets a principal hand an existing role to a service: create a Lambda with an admin role and invoke it
  2. Other primitives: iam:CreatePolicyVersion, AttachRolePolicy, PutUserPolicy, UpdateAssumeRolePolicy on admin roles
  3. Effective access needs graph analysis across identity, resource and trust policies (e.g. PMapper, Cloudsplaining)
  4. Scope PassRole to specific role ARNs with the iam:PassedToService condition; never PassRole on Resource "*"
  5. Detect: CreateFunction or UpdateFunctionConfiguration passing a privileged role, then IAM changes by that role

If the interviewer pushes back

  • How do SCPs and permission boundaries each limit this, and which actions must be denied to stop boundary removal?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.