VPC Lattice connects services across VPCs and accounts through a service network, with access governed by IAM-style auth policies rather than by network routing. A permissive auth policy (a wildcard principal, or no policy at all) lets any principal that can reach the service network call the registered services, turning Lattice into a cross-account application-layer pivot.
Enumerating the mesh#
aws vpc-lattice list-service-networks
aws vpc-lattice list-services
aws vpc-lattice list-service-network-service-associations --service-network-identifier <id>
aws vpc-lattice get-auth-policy --resource-identifier <service-or-network-arn>
Exploitation notes#
- An auth policy with
"Principal":"*"orAWS:"*"and no condition exposes the service to any authenticated caller on the network. - Lattice bypasses traditional security-group and subnet boundaries, so a service unreachable by routing may still be callable through the service network.
- Service associations across accounts make a permissive policy a cross-account reach, not just an in-account one.
Tools#
- AWS CLI (
vpc-lattice ...): service-network, service, and auth-policy enumeration. - ScoutSuite / Prowler: flag permissive Lattice auth policies.