IAM role can escalate privileges through iam:CreateLoginProfile

Limit permission to create other IAM users’ console login profiles to required administration.

Description

iam:CreateLoginProfile can set a console password for an IAM user that does not yet have a login profile. A role user allowed to target a privileged user can create a new console access path.

Other sign-in controls, including MFA, still apply. Creating the profile does not increase the target user’s permissions, but creates another way to use them.

Potential impact

  • A new account access path: a user without a console password can gain browser-based access.
  • Privilege escalation: other sign-in controls permitting, the caller can access the console as a privileged user.
  • Delayed detection: unauthorized profile creation can be hard to distinguish from normal administration.

Remediation

  • Remove iam:CreateLoginProfile from roles that do not manage login profiles.
  • Limit required permission to dedicated administrators and approved target users.
  • Review profile-creation events and preserve the target user’s sign-in controls, including MFA.

Examples

These are permission-policy excerpts; configure the role trust policy separately.

Before

hcl
resource "aws_iam_role" "example" {
  name = "cosmic"
}

resource "aws_iam_role_policy" "example" {
  name = "test_inline_policy"
  role = aws_iam_role.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:CreateLoginProfile",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

After

hcl
resource "aws_iam_role" "example" {
  name = "cosmic"
}

resource "aws_iam_role_policy" "example" {
  name = "inline_policy_run_instances"
  role = aws_iam_role.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

The after example removes login-profile creation from this policy on the same role and leaves EC2 describe permissions. It does not remove existing login profiles or other attached policies.

References