Lateral movement

Service Account Privilege Escalation – Update Function (Resource Scope)


The Service account '{GcpIamServiceAccount}' has an IAM policy containing permission that allow privilege escalation, at the resource level ({GcpIamServiceAccount.PolicyBindings.Policy.Scope}). The permission cloudfunctions.functions.update allows the service account to update existing services with higher permissions than their own. The service account can then utilize these services to perform API calls that the service account may not be authorized to perform. The role containing these permissions is '{GcpIamServiceAccount.PolicyBindings.Role}'.
  • Recommended Mitigation

    Evaluate the Service Account's permissions and consider removing the binding to {GcpIamServiceAccount.PolicyBindings.Role} or the permission: cloudfunctions.functions.update