IAM role can escalate privileges through iam:UpdateLoginProfile

Restrict IAM console-password changes to approved administrators and target users.

Description

Broad iam:UpdateLoginProfile permission allows changes to other IAM users’ existing console passwords. If the permission is effective for a privileged user and login requirements are met, that user’s permissions can be abused.

The operation changes an existing login profile; it does not grant permission to create one. Changing a password does not bypass MFA or other login restrictions.

Potential impact

  • Access through the user account can expose the data and resources within its permissions.
  • Unapproved password changes can interrupt legitimate user access.

Remediation

  • Remove iam:UpdateLoginProfile from roles that do not need it, and scope necessary access to approved user ARNs.
  • Limit password administration to help-desk or security administrators, with additional approval for privileged users.
  • Review login-profile changes and subsequent sign-ins, and retain existing authentication controls such as MFA.

Examples

These are role-permission excerpts. The required assume_role_policy is omitted; configure it separately so only approved principals can use the role.

Before

hcl
resource "aws_iam_role" "example" {
  name = "cosmic"
}

resource "aws_iam_role_policy" "example" {
  name = "test_inline_policy"
  role = aws_iam_role.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:UpdateLoginProfile",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

After

hcl
resource "aws_iam_role" "example" {
  name = "cosmic"
}

resource "aws_iam_role_policy" "example" {
  name = "inline_policy_run_instances"
  role = aws_iam_role.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

Explanation:

  • Before: Allows login-profile changes without limiting the target users. Actual login and impact depend on the target account and applicable controls.
  • After: Limits the example policy on the same role to EC2 queries. Remove profile-changing access from other policies too, and narrow ec2:Describe* to required queries.

References