Case 38CAED · Cloud · L5 Expert
AWS IAM Privilege Escalation Paths
Practise as: Explain it · Interview
Interview questionA CI role has iam:PassRole, lambda:CreateFunction and lambda:InvokeFunction but no admin policy. Why is it admin, and how do you find such paths at scale?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- PassRole lets a principal hand an existing role to a service: create a Lambda with an admin role and invoke it
- Other primitives: iam:CreatePolicyVersion, AttachRolePolicy, PutUserPolicy, UpdateAssumeRolePolicy on admin roles
- Effective access needs graph analysis across identity, resource and trust policies (e.g. PMapper, Cloudsplaining)
- Scope PassRole to specific role ARNs with the iam:PassedToService condition; never PassRole on Resource "*"
- Detect: CreateFunction or UpdateFunctionConfiguration passing a privileged role, then IAM changes by that role
If the interviewer pushes back
- How do SCPs and permission boundaries each limit this, and which actions must be denied to stop boundary removal?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.