Glossary

    Privilege Escalation

    Identity & Access

    Privilege Escalation in AWS occurs when a principal obtains permissions beyond what was intended. This typically happens through IAM misconfigurations that allow a user to modify their own permissions or create new high-privilege identities.

    Common AWS Privilege Escalation Paths

    • iam:CreatePolicy + iam:AttachUserPolicy - create an admin policy and attach it to yourself
    • iam:PassRole + lambda:CreateFunction - pass a high-privilege role to a new Lambda function you control
    • iam:CreateLoginProfile - create console access for another user, then log in as them
    • iam:UpdateAssumeRolePolicy - modify a role's trust policy to allow yourself to assume it
    • sts:AssumeRole on overly permissive roles - assume a role with broader permissions

    Prevention

    • Never grant iam:* - scope IAM permissions carefully
    • Use permission boundaries to cap maximum permissions
    • Restrict iam:PassRole to specific role ARNs
    • Monitor for privilege escalation with GuardDuty and CloudTrail

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.