Description
Overly broad iam:AttachUserPolicy permissions can let an IAM user attach powerful managed policies to themselves or other users. This can enable privilege escalation if attachment and subsequent actions are not blocked by other limits.
Attachment does not automatically remove permissions boundaries, organization policies or explicit denies. Review both the target users and policies that can be attached.
Potential impact
- Users can increase their own resource access or modification rights without approval.
- Expanding another user’s permissions can increase the damage caused by credential misuse.
Remediation
Remove unnecessary iam:AttachUserPolicy and perform administration through approved roles. Where needed, specify target user ARNs in Resource and limit policies with iam:PolicyARN conditions. Review self-modification paths and logs, and verify intended operations and denial of unapproved attachments.
Examples
This comparison reduces allowed actions in the same user’s inline policy.
Before
resource "aws_iam_user" "example" {
name = "cosmic"
}
resource "aws_iam_user_policy" "example" {
name = "test_inline_policy"
user = aws_iam_user.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:AttachUserPolicy",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This allows the user to attach managed policies across users, including themselves.
After
resource "aws_iam_user" "example" {
name = "cosmic"
}
resource "aws_iam_user_policy" "example" {
name = "test_inline_policy"
user = aws_iam_user.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This grant now contains only EC2 describe actions. Also review attachment permissions and unnecessary describe access from other policies.