Lateral movement

Privileged Role – Policy Version

Risk Level

Hazardous (3)

Platform(s)
Compliance Frameworks

Description

An IAM Role is an identity with permission policies that determine what the identity can do in AWS. A role does not have any credentials (password or access keys) associated with it. Instead of being uniquely associated with one person, a role is intended to be assumable by anyone who needs it. The role {AwsIamRole} was found with permissive permissions that allow for the ability to create or change a managed policy's version. Managed policies often hold a list of previous versions of the permissions they grant. By creating a new versions with additional permissions, or reverting to an old more permissive version, an attacker may be able to escalate their privileges and achieve account takeover.
  • Recommended Mitigation

    Review the role's policy, {AwsIamRole.Policies}, and consider removing any of the following actions: iam:CreatePolicyVersion, iam:SetDefaultPolicyVersion.