Lateral movement

User Privilege Escalation – Service Update (Project Scope)

Description

The User '{GcpUser}' has an IAM policy containing permissions that allow privilege escalation, at the project level. One or more of the existing permissions allow the user to update existing services with higher permissions than their own. The user can then utilize these services to perform API calls that the user may not be authorized to perform. The role containing these permissions is '{GcpUser.PolicyBindings.Role}'