Skip to content

H3-2024-0004

AWS Privilege Escalation - iam:PutRolePolicy

Category SECURITY_MISCONFIGURATION
Base Score 9

Description

An AWS user or role assigned the iam:PutRolePolicy permission, that is not an administrator, can assign an AWS role administrator permissions.

Impact

This misconfiguration permits an AWS user to escalate to administrator permissions.

References