CloudFormation can deploy a stack using a service role rather than your own permissions. With iam:PassRole and cloudformation:CreateStack, you pass a privileged role and submit a template that provisions whatever that role can create, including new IAM principals or policies.
Deploy with a passed role#
# template.yaml creates, for example, an admin user or attaches a policy
aws cloudformation create-stack --stack-name x \
--template-body file://template.yaml \
--role-arn arn:aws:iam::<acct>:role/<privileged-stack-role> \
--capabilities CAPABILITY_NAMED_IAM
Because the stack role performs the resource creation, a template that creates an AWS::IAM::User with an access key, or attaches AdministratorAccess, succeeds even though your own principal cannot.
Exploitation notes#
CAPABILITY_NAMED_IAMis required when the template touches IAM; the role, not you, must hold the IAM permissions.- Updating an existing stack that already carries a privileged role is the existing-resources variant and needs no
PassRole. - Stack outputs can return the created access key directly, so no separate retrieval step is needed.
Tools#
- AWS CLI (
cloudformation create-stack). - Pacu: CloudFormation privesc and data modules.