iam:PassRole + Wildcard: The Privilege Escalation Hiding in Plain Sight
A developer account with nothing but lambda:CreateFunction and a wildcard iam:PassRole can walk itself up to full Administrator — no exploit, no misconfigured bucket, just permissions doing exactly what they were asked to do.
No exploit. No CVE. Just IAM doing exactly what you told it to.
This one doesn’t show up as a vulnerability scan finding or a CVE — it’s a permissions grant that looks completely reasonable in a policy review, right up until someone connects the dots.