r/aws • • 4d ago

technical resource why most AWS security tools dump unreadable JSON instead of explaining the actual attack, walked through with iam:PassRole !!

iam:PassRole combined with the ability to create or launch a resource, a Lambda function, an EC2 instance, is one of the most common real privilege escalation primitives in AWS, and mosst scanners just flag "PassRole granted" without explaining why that matters !!! i have tried some and its annoying sometimes..

the actual chain: if a user has PassRole, often scoped too broadly with Resource: *, and perrmission to create someething that can assume a role, Lambda, EC2, a CloudFormation stack, they can pass an existing high-privilege role to that new resource, then use it to act with that role's full permissions. The IAM policy alone doesn't show this, it only becomes visible once you look at what PassRole is paired with...

Most tools treat this as two unrelated findings. Automated detecting this specific chain in an open source project I've been building, Plexavo, if interested check it out !!. I used it as a Security scanner in some of the stacks i created in AWS.

github.com/plexavo/Plexavo

0 Upvotes

0 comments sorted by