H3-2024-0007
AWS Privilege Escalation - iam:UpdateLoginProfile
Category | SECURITY_MISCONFIGURATION |
Base Score | 7 |
Description
An AWS user or role assigned the iam:UpdateLoginProfile permission, that is not an administrator, can change a password for another user with more permissions.
Impact
This misconfiguration permits an AWS user or role to compromise another user with more permissions.