Description
iam:CreateLoginProfile can set a console password for an IAM user that does not yet have a login profile. A role user allowed to target a privileged user can create a new console access path.
Other sign-in controls, including MFA, still apply. Creating the profile does not increase the target user’s permissions, but creates another way to use them.
Potential impact
- A new account access path: a user without a console password can gain browser-based access.
- Privilege escalation: other sign-in controls permitting, the caller can access the console as a privileged user.
- Delayed detection: unauthorized profile creation can be hard to distinguish from normal administration.
Remediation
- Remove
iam:CreateLoginProfilefrom roles that do not manage login profiles. - Limit required permission to dedicated administrators and approved target users.
- Review profile-creation events and preserve the target user’s sign-in controls, including MFA.
Examples
These are permission-policy excerpts; configure the role trust policy separately.
Before
hcl
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "test_inline_policy"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:CreateLoginProfile",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
After
hcl
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "inline_policy_run_instances"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
The after example removes login-profile creation from this policy on the same role and leaves EC2 describe permissions. It does not remove existing login profiles or other attached policies.