During a cloud assessment, a tester discovers an IAM user has the iam:PassRole and ec2:RunInstances permissions attached, but no direct administrative privileges. An IAM role named AdminRole with full administrative access also exists in the account. Which technique would allow the tester to escalate privileges to that of an administrator?
- APerform a Golden SAML attack against the federated identity provider
- BBrute-force the AWS root account password using hashcat
- CLaunch an EC2 instance with the AdminRole attached via PassRole, then retrieve temporary credentials from the instance metadata service
- DModify the S3 bucket policy to grant public read/write access
Show answer & explanationAnswer & explanation
Correct answer: C. Launch an EC2 instance with the AdminRole attached via PassRole, then retrieve temporary credentials from the instance metadata service
When a user has both iam:PassRole and ec2:RunInstances, they can launch a new EC2 instance and attach a more privileged IAM role (like AdminRole) to it; once running, the instance's metadata service exposes temporary credentials for that role, effectively granting the attacker admin-level access. Modifying S3 policies requires separate S3 permissions not mentioned, Golden SAML requires compromising ADFS token-signing certificates, and brute-forcing the root password is impractical and unrelated to the permissions described.
Why the other options are wrong
- A. Golden SAML requires ADFS token-signing key compromise, unrelated to the IAM permissions given.
- B. Brute-forcing the root password is not feasible and unrelated to the described IAM misconfiguration.
- D. No S3 permissions were mentioned, and this doesn't lead to admin role assumption.
IAM PassRole Privilege Escalation
A cloud privilege escalation technique where a user with iam:PassRole and a resource-launching permission (like ec2:RunInstances) attaches a highly privileged role to a new resource to inherit its permissions.
- Requires iam:PassRole plus a launch permission (EC2, Lambda, etc.)
- Credentials retrieved via instance metadata service after launch
- Common AWS misconfiguration finding in cloud pentests
Memory trick: 'PassRole + RunInstances = pass the crown to a new instance and wear it yourself'