Overly Broad AWS Default Roles Could Enable Cross-Service Privilege Escalation

· Original article ↗

Summary

Aqua researchers found that overly permissive default IAM roles in AWS services and the Ray framework could let attackers misuse S3 access to tamper with other services and potentially escalate privileges. AWS changed several policies and guidance.

Key points

  • Researchers found broad S3 permissions, including AmazonS3FullAccess, in default roles associated with SageMaker, Glue, EMR, and the Ray framework.
  • An attacker able to run a Glue job or use a SageMaker notebook under an affected role could access S3 buckets used by other services and modify stored assets.
  • A malicious Hugging Face model can execute code through SageMaker's model-loading and prediction functions; the researchers say setting trust_remote_code=False does not prevent this SageMaker behavior.
  • Tampering with CloudFormation templates or CDK assets could enable privilege escalation when those assets are later deployed by a privileged user.
  • AWS narrowed permissions for default roles in SageMaker, Glue, and EMR, updated Lightsail guidance, and notified affected users to review existing roles.
  • Aqua recommends removing broad S3 permissions, restricting roles to required buckets and actions, and auditing IAM policies; the researchers said they had not received a response from Ray's security team.

Article Details

Attack Vectors
  • A malicious Hugging Face model containing inference.py can execute code when imported into Amazon SageMaker AI. In the researchers’ proof of concept, the code used the SageMaker execution role’s broad S3 access to inject a backdoor into AWS Glue job scripts.
  • A user or attacker able to create or modify AWS Glue jobs can run a job under AWSGlueServiceRole, which the researchers found had AmazonS3FullAccess, to enumerate and alter S3 assets used by other services.
  • A Glue job can modify a CloudFormation template before deployment to add an administrative IAM role, if the user deploying the stack has permission to manage IAM roles.
  • The researchers found that Ray’s default ray-autoscaler-v1 role had AmazonS3FullAccess hardcoded in its source code. They warned that compromise of a Ray EC2 instance could permit tampering with other services’ S3 assets.
Defensive Notes
  • Audit existing IAM roles, remove AmazonS3FullAccess and similarly broad permissions where unnecessary, and restrict S3 access to the buckets and actions each service requires.
  • AWS changed default-role permissions for Amazon SageMaker AI, AWS Glue, and Amazon EMR, updated Amazon Lightsail guidance, and notified affected users that existing roles require attention.
  • Aqua Platform’s ‘IAM Role Policies’ plugin flags broad managed and inline IAM policies, including wildcard resources and s3:* actions.
  • The researchers said they had not received a response from the Ray project security team at the time of writing.

MITRE ATT&CK

Vendors

Products

Amazon EMRAmazon EMR: The default AmazonEMRStudio_RuntimeRole_<Epoch-time> role is automatically assigned the AmazonS3FullAccess policy, allowing EMR notebooks to run with full access to S3.Amazon LightsailWe also saw some reference in the Amazon Lightsail AWS documentation that instructs users to attach the AmazonS3FullAccess policy to a role or user to support the WordPress Offload Media plugin.Amazon S3Inline policies include wildcard actions like s3:*, which may unintentionally allow full access to sensitive services such as Amazon S3.Amazon SageMaker AIAmazon SageMaker AI: SageMaker offers two ways of creating a domain (Single user or Quick Setup and Setup for Organizations).Aqua PlatformAqua Platform users can leverage the ‘IAM Role Policies’ plugin as part of their security scans to detect overly permissive IAM configurations.AWS CDKthe internal behaviour of services like CloudFormation, SageMaker, Glue, EMR, as well as tools like the AWS CDK – escalating their privileges far beyond the original scope of the role.AWS GlueFor example,  when a user first accesses AWS Glue through the Management Console, a default role AWSGlueServiceRole is automatically created.AWS IAMAWS IAM (Identity and Access Management) controls who can access AWS resources and what actions they can perform.CloudFormationGaining full access to S3 allows an attacker to manipulate the internal behaviour of services like CloudFormation, SageMaker, Glue, EMR, as well as tools like the AWS CDK – escalating their privileges far beyond theRayWe found these flaws across several AWS services, including SageMaker, Glue, and EMR, as well as in popular open-source projects like Ray.

Tools

Related Articles