Product
CloudFormation
- First Reported
- Apr 29, 2025
- Latest Reported
- Apr 29, 2025
Reported Context (1)
- Gaining full access to S3 allows an attacker to manipulate the internal behaviour of services like CloudFormation, SageMaker, Glue, EMR, as well as tools like the AWS CDK โ escalating their privileges far beyond the Overly Broad AWS Default Roles Could Enable Cross-Service Privilege Escalation
MITRE ATT&CK (4)
Vendors (2)
Products (9)
Tools (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.