IAM role can escalate privileges through iam:CreateAccessKey

Restrict creation of other IAM users’ access keys to approved administrative work.

Description

Broad iam:CreateAccessKey permission can let a role user issue a new access key for another IAM user and call APIs with that user’s permissions. Target-user restrictions and effective policies still govern issuance and use.

Creating a key for a more privileged user can provide long-term credentials that enable privilege misuse.

Potential impact

  • Impersonation of a privileged user: the new key can authorize operations allowed for its owner.
  • Persistent credentials: an issued key can remain available for continued misuse.
  • Delayed detection: unauthorized issuance can be hard to distinguish from legitimate administration.

Remediation

  • Remove iam:CreateAccessKey from roles that do not manage keys.
  • Restrict required issuance to dedicated administrators and approved target users.
  • Monitor key creation and prefer role-based temporary credentials where possible.

Examples

These are permission-policy excerpts. Configure the role’s trust policy separately.

Before

hcl
resource "aws_iam_role" "example" {
  name = "cosmic"
}

resource "aws_iam_role_policy" "example" {
  name = "test_inline_policy"
  role = aws_iam_role.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:CreateAccessKey",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

After

hcl
resource "aws_iam_role" "example" {
  name = "cosmic"
}

resource "aws_iam_role_policy" "example" {
  name = "inline_policy_run_instances"
  role = aws_iam_role.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

The after example removes key issuance from this policy on the same role and leaves EC2 describe permissions. Review other attached policies and keys already issued separately.

References