IAM misconfigurations

EC2 Instance with Administrator Privileges

Platform(s)
Compliance Frameworks

Brazilian General Data Protection (LGPD), CCM-CSA, CCPA, cis_8, CPRA, Data Security Posture Management (DSPM) Best Practices, essential_8_au, GDPR, HITRUST, ISO 27701, iso_27001_2022, iso_27002_2022, Mitre ATT&CK, New Zealand Information Security Manual, NIST 800-171, NIST 800-190, NIST 800-53, PDPA, pipeda, STIG K8s, UK Cyber Essentials

Description

The AWS EC2 Instance was found to have full administrative privileges to your account. Instance Profiles with full administrative privileges attached grant unrestricted access (Action: '*') to any resources on the account (Resource: '*'). In the event that the asset is compromised, this may potentially lead to full account takeover.