Lateral movement

Privileged Managed Policy – Assume Role

Risk Level

Hazardous (3)

Platform(s)
Compliance Frameworks

Description

An IAM Managed Policy is an object in AWS that, when associated with an identity or resource, defines their permissions. The policy {AwsIamManagedPolicy} was found with permissive permissions that allows the user the ability to assume any role, temporarily granting them any privileges given to that role. By allowing an entity to assume any role on the account, an attacker may choose to assume a highly privileged role, which may lead to full account takeover.
  • Recommended Mitigation

    Review the policy and consider removing any of the following actions: sts:AssumeRole