Skip to content

Conversation

@lambdasawa
Copy link
Contributor

This PR adds a new privilege escalation technique for AWS AppRunner service. The technique demonstrates how an attacker with iam:PassRole and apprunner:CreateService permissions can escalate privileges by creating an AppRunner service with an attached IAM role.

This attack pattern is similar to the ECS privilege escalation technique that exploits ecs:RegisterTaskDefinition, where an attacker can gain access to IAM role credentials by deploying a malicious container.

@carlospolop
Copy link
Collaborator

Nice and easy, thanks @lambdasawa !

@carlospolop carlospolop merged commit 2ea8119 into HackTricks-wiki:master Aug 1, 2025
github-actions bot pushed a commit that referenced this pull request Aug 29, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants