IAM user permissions for iam:AttachUserPolicy need review

Restrict policies that a user can attach to themselves or other users.

Description

Overly broad iam:AttachUserPolicy permissions can let an IAM user attach powerful managed policies to themselves or other users. This can enable privilege escalation if attachment and subsequent actions are not blocked by other limits.

Attachment does not automatically remove permissions boundaries, organization policies or explicit denies. Review both the target users and policies that can be attached.

Potential impact

  • Users can increase their own resource access or modification rights without approval.
  • Expanding another user’s permissions can increase the damage caused by credential misuse.

Remediation

Remove unnecessary iam:AttachUserPolicy and perform administration through approved roles. Where needed, specify target user ARNs in Resource and limit policies with iam:PolicyARN conditions. Review self-modification paths and logs, and verify intended operations and denial of unapproved attachments.

Examples

This comparison reduces allowed actions in the same user’s inline policy.

Before

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "test_inline_policy"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:AttachUserPolicy",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This allows the user to attach managed policies across users, including themselves.

After

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "test_inline_policy"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This grant now contains only EC2 describe actions. Also review attachment permissions and unnecessary describe access from other policies.

References