IAM role can escalate privileges through lambda:UpdateFunctionCode

Limit Lambda code changes to approved deployment roles and functions.

Description

Broad lambda:UpdateFunctionCode permission allows arbitrary changes to existing Lambda function code. When the changed code runs, it can access data and perform AWS operations with the function’s execution-role permissions, creating a potential indirect escalation path.

Permission to change code does not itself grant invocation permission. Review the actual execution path, versions and aliases in use, and the execution role’s permissions.

Potential impact

  • Changed code, once executed, can expose or alter data accessible to the execution role.
  • Function behavior can be altered or service operations disrupted.

Remediation

  • Remove lambda:UpdateFunctionCode from roles that do not need it, and restrict access to approved CI/CD roles and target function ARNs.
  • Keep execution roles least privileged and require review and approval for sensitive code deployments.
  • Monitor code changes and verify that executed versions and aliases point to approved deployments.

Examples

These are role-permission excerpts. Configure the omitted, required assume_role_policy separately to trust only approved principals.

Before

hcl
resource "aws_iam_role" "example" {
  name = "cosmic"
}

resource "aws_iam_role_policy" "example" {
  name = "test_inline_policy"
  role = aws_iam_role.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "lambda:UpdateFunctionCode",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

After

hcl
resource "aws_iam_role" "example" {
  name = "cosmic"
}

resource "aws_iam_role_policy" "example" {
  name = "inline_policy_run_instances"
  role = aws_iam_role.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

Explanation:

  • Before: Allows code changes without restricting the target functions. Impact depends on execution of the changed code and the execution role’s permissions.
  • After: Limits the example policy on the same role to EC2 queries. Remove code-changing access from other policies too, and allow only required ec2:Describe* queries.

References