AttachUserPolicy

iam:AttachUserPolicy attaches a managed policy to a user. If you hold it for your own user, attach the AWS-managed AdministratorAccess and you are administrator in one call.

Attach admin#

bash
aws iam attach-user-policy --user-name <you> \
  --policy-arn arn:aws:iam::aws:policy/AdministratorAccess

Exploitation notes#

  • AdministratorAccess is an AWS-managed policy present in every account, so no policy creation is needed.
  • Works only against users; the role and group equivalents are AttachRolePolicy and AttachGroupPolicy.

Tools#

  • AWS CLI (iam attach-user-policy).
  • Pacu (iam__privesc_scan).

References#

Cookie Consent

We use cookies to enhance your experience. Learn more