When a principal can write IAM policy, it can write itself to administrator. These are the most direct escalations in AWS: a single iam: write, no new resource, no host. They split into three shapes: changing which version of a managed policy is active, attaching a managed policy, and inlining a policy document.
Managed policy versions#
- CreatePolicyVersion: publish a new default version of a policy you can edit, granting full access.
- SetDefaultPolicyVersion: activate an existing, more permissive version.
Attaching managed policies#
- AttachUserPolicy: attach
AdministratorAccessto a user you control. - AttachGroupPolicy: attach a privileged policy to a group you belong to.
- AttachRolePolicy: attach a privileged policy to a role you can assume.
Inlining policy documents#
- PutUserPolicy: inline an allow-all document onto a user.
- PutGroupPolicy: inline an allow-all document onto a group.
- PutRolePolicy: inline an allow-all document onto a role.