A role is assumable by whoever its trust policy allows. sts:AssumeRole returns temporary credentials for the role, and because trust policies are frequently written too broadly (a whole account as principal, a wildcard, or a third-party account with no external ID), role assumption is both a lateral-movement and an escalation primitive.
Assuming a role#
aws sts assume-role \
--role-arn arn:aws:iam::<acct>:role/<role> \
--role-session-name s --query Credentials
# export AccessKeyId / SecretAccessKey / SessionToken and continue as the role
What folds in here#
- Cross-account: trust policies that name another account (or
root), letting any principal there assume in. - Confused deputy: third-party-vendor roles assumable without the external ID that was meant to scope them.
Finding assumable roles#
Read trust documents from the enumeration dump and look for Principal values broader than a single role ARN, and for sts:AssumeRole statements missing a Condition on sts:ExternalId.