Logo The David Page
  • Home
  • About
  • Featured Posts
  • Recent Posts
  • Posts
  • Dark Theme
    Light Theme Dark Theme System Theme
Logo Inverted Logo
  • Posts
  • Cloud
    • AWS
      • CloudFront
        • CloudFront Flat-Rate Migration
      • Networking & VPC
        • Cross-AZ Data Transfer Cost
        • MTU 9001 / PMTUD Black Hole
        • NAT Gateway & S3 Gateway Endpoint
      • DynamoDB
        • DynamoDB On-Demand Ceiling
      • CloudWatch
        • CloudWatch Logs Insights Cost
      • S3
        • Glacier Small-Files Cost Trap
        • Incomplete Multipart Uploads
      • IAM
        • iam:PassRole Privilege Escalation
      • EC2
        • HTTP 429 – Gemini API on AWS
        • IMDSv2 Hop Limit / Containers
      • Lambda
        • Lambda /tmp Warm Start Persistence
      • RDS
        • RDS Proxy & CloudWatch Cost
    • Azure
      • Front Door
        • WAF Policy ArmResourceId Error
Hero Image
iam:PassRole + Wildcard: The Privilege Escalation Hiding in Plain Sight

A developer account with nothing but lambda:CreateFunction and a wildcard iam:PassRole can walk itself up to full Administrator — no exploit, no misconfigured bucket, just permissions doing exactly what they were asked to do. Hi everyone 👋 This one doesn’t show up as a vulnerability scan finding or a CVE — it’s a permissions grant that looks completely reasonable in a policy review, right up until someone connects the dots. 😱 The convenient habit To make deployments easier, it’s extremely common to grant developer accounts iam:PassRole against * (a wildcard covering every role in the account). The reasoning is simple and, on its own, sounds harmless: developers need to attach an IAM role to whatever they deploy — a Lambda function, an EC2 instance — and wildcarding PassRole means nobody has to update a policy every time a new role gets created.

  • AWS
  • IAM
  • Security
  • Privilege Escalation
Saturday, August 1, 2026 Read
Navigation
  • About
  • Featured Posts
  • Recent Posts
Contact me:
  • hi@thedavidlee.space

© 2026 Copyright.