IAM user has excessive iam:UpdateLoginProfile permissions

Restrict permission to change other users’ console passwords.

Description

Broad iam:UpdateLoginProfile permission can allow another IAM user’s console password to be changed. If the target is privileged and other sign-in controls permit access, its account can provide stronger permissions. Password-changing permission does not itself disable MFA.

Potential impact

  • A password change can disrupt the legitimate user’s console access.
  • A principal that successfully signs in can perform operations allowed for the target user.

Remediation

Remove iam:UpdateLoginProfile permission from users who do not administer passwords. Limit required administration to approved target users, and review password changes and sign-in controls such as MFA.

Examples

The second policy grants the same user only EC2 describe permissions. Remove or restrict password-changing permissions in other policies, and separately check passwords and account state that have already changed.

Before

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "test_inline_policy"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:UpdateLoginProfile",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

After

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "inline_policy_read_only"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

References