Logo The David Page
  • Home
  • About
  • North Star
  • Recent Posts
  • Posts
Logo Inverted Logo
  • Tags
  • Amazon Bedrock
  • Arm64
  • AWS
  • Azure
  • Azure CLI
  • Benchmark
  • CDN
  • CloudFront
  • CloudWatch
  • Containers
  • Cost Optimization
  • Databases
  • Docker
  • DynamoDB
  • EC2
  • ECR
  • FinOps
  • Front Door
  • Gemini API
  • Glacier
  • Graviton
  • IAM
  • Kubernetes
  • Lambda
  • NAT Gateway
  • Networking
  • Node.js
  • Observability
  • Performance
  • Privilege Escalation
  • Rate Limiting
  • RDS
  • RDS Proxy
  • Reliability
  • S3
  • Scalability
  • Security
  • Serverless
  • Software Architecture
  • Storage
  • System Design
  • Troubleshooting
  • VPC
  • WAF
Hero Image
iam:PassRole + Wildcard: The Privilege Escalation Hiding in Plain Sight

A developer account with nothing but lambda:CreateFunction and a wildcard iam:PassRole can walk itself up to full Administrator — no exploit, no misconfigured bucket, just permissions doing exactly what they were asked to do. No exploit. No CVE. Just IAM doing exactly what you told it to. This one doesn’t show up as a vulnerability scan finding or a CVE — it’s a permissions grant that looks completely reasonable in a policy review, right up until someone connects the dots.

  • AWS
  • IAM
  • Security
  • Privilege Escalation
Saturday, August 1, 2026 Read
Navigation
  • About
  • North Star
  • Recent Posts
Contact me:
  • hi@thedavidlee.space

© 2026 David Lee.