VPC Lattice

VPC Lattice connects services across VPCs and accounts through a service network, with access governed by IAM-style auth policies rather than by network routing. A permissive auth policy (a wildcard principal, or no policy at all) lets any principal that can reach the service network call the registered services, turning Lattice into a cross-account application-layer pivot.

Enumerating the mesh#

bash
aws vpc-lattice list-service-networks
aws vpc-lattice list-services
aws vpc-lattice list-service-network-service-associations --service-network-identifier <id>
aws vpc-lattice get-auth-policy --resource-identifier <service-or-network-arn>

Exploitation notes#

  • An auth policy with "Principal":"*" or AWS:"*" and no condition exposes the service to any authenticated caller on the network.
  • Lattice bypasses traditional security-group and subnet boundaries, so a service unreachable by routing may still be callable through the service network.
  • Service associations across accounts make a permissive policy a cross-account reach, not just an in-account one.

Tools#

  • AWS CLI (vpc-lattice ...): service-network, service, and auth-policy enumeration.
  • ScoutSuite / Prowler: flag permissive Lattice auth policies.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more