Q: An IAM user has `ec2:RunInstances` permissions, but they do NOT have permissions to read S3 buckets. However, they also have the `iam:PassRole` permission for an existing `S3Admin` EC2 Role. Explain how this user can escalate their privileges to steal S3 data.
This is a classic IAM privilege escalation path.
#Security #Security #L2 #DevSecOps #Compliance #IAM
🎙️ Candidate Opening & Architectural Context
""When an interviewer asks how I respond to this security vulnerability, I emphasize immediate blast-radius containment. The interviewer is testing: IAM PassRole abuse, privilege escalation vectors.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
This is a classic IAM privilege escalation path.
- Launch a new EC2 instance via the CLI.
- During the launch, they "pass" the
S3Adminrole to the instance, effectively attaching it. - Once the instance boots, they SSH into it (or execute commands via User Data).
2️⃣
Remediation & Permanent Safeguards
The user cannot read the S3 bucket directly. However, because they possess iam:PassRole along with ec2:RunInstances, they can:
- From inside the instance, they execute
aws s3 cpcommands. The command succeeds because the instance is using the temporary credentials of the highly privilegedS3Adminrole. The user bypasses their own restrictions and steals the data via the machine's identity.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Launch a new EC2 instance via the CLI.."
⚡ 60-Second Elevator Pitch Talking Points
- Launch a new EC2 instance via the CLI.
- During the launch, they "pass" the S3Admin role to the instance, effectively attaching it.
- Once the instance boots, they SSH into it (or execute commands via User Data).
Advertisement