IAM Trust Policies - PrivEsc
Abusable AWS IAM Trust Policies that can lead to compromise or privilege escalation
Abusing Vulnerable Trust Policies
Poorly written IAM Trust Policies can lead to compromise
AWS Service Trust Policy
Bad policy
This policy allows the Lambda service in any AWS account to assume the role. An attacker only needs to know the ARN of the role
Better policy
The role assumption is restricted to a particular lambda function within a particular AWS account but other conditions can be specified too
Resources
Last updated