logo

Database

Aws Privilege Escalation By Policy Versions

Description

Detects IAM policies that allow privilege escalation through policy version manipulation. This vulnerability occurs when a policy allows both creating new policy versions and setting default versions (iam:CreatePolicyVersion and iam:SetDefaultPolicyVersion), or grants full IAM permissions (iam:*), enabling users to potentially escalate their privileges.

Weakness:

005 - Privilege escalation

Category: Access Subversion

Detection Strategy

    Scans IAM policy statements looking for 'Allow' effects combined with risky IAM permissions

    Triggers when a policy grants both iam:CreatePolicyVersion AND iam:SetDefaultPolicyVersion permissions

    Triggers when a policy grants full IAM permissions through iam:*

    Only flags policies where these permissions are explicitly allowed and have resources specified

Severity v4.0

5.9

Medium

Method ID

CSPM-EIESN

Technique

CSPM

Target

AWS

Technology

IAM

CWE ID(s)

CWE-78