Skip to content

H3-2024-0007

AWS Privilege Escalation - iam:UpdateLoginProfile

Category SECURITY_MISCONFIGURATION
Base Score 7

Description

An AWS user or role assigned the iam:UpdateLoginProfile permission, that is not an administrator, can change a password for another user with more permissions.

Impact

This misconfiguration permits an AWS user or role to compromise another user with more permissions.

References