Skip to main content

CCC.IAM.TH08: Privilege Escalation via Indirect Role Usage

Threat ID:CCC.IAM.TH08
Title:Privilege Escalation via Indirect Role Usage
Description:

An identity principal possesses specific, highly privileged permissions, such as the ability to pass roles or impersonate service accounts, that allow it to leverage the permissions of a different, more privileged role. Even without being able to directly assume the target role, the principal can attach it to a new resource they control and then use that resource to perform unauthorized actions.

Related Capabilities

IDTitleDescription
CCC.IAM.F02IAM UsersAbility to create, manage, list and delete IAM users. IAM user represents a single person or application.
CCC.IAM.F06IAM Roles / Service PrincipalsAbility to create, manage, list and delete IAM roles. IAM role is an identity for applications or services to access resources.
CCC.IAM.F15Role Assumption / DelegationAbility to temporarily assume another role or delegate access. Commonly used for user impersonation or temporary privilege elevation.

External Mappings

Reference IDEntry IDStrengthRemarks
MITRE-ATT&CK
T1548.006
0
Abuse Elevation Control Mechanism: Temporary Elevated Cloud Access