logo

AWS Execution Roles Enable Subtle Privilege Escalation in SageMaker and EC2

ID: 75f7bba9-0f8d-5097-bbf4-c5e4209bf290

STIX ID: report--75f7bba9-0f8d-5097-bbf4-c5e4209bf290

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-05

Date Updated: 2026-04-21

Author: Abinaya

...
...

This report details a persistent privilege-escalation technique against AWS compute services where attackers who can stop/start instances or notebooks and modify boot or lifecycle configurations inject scripts (via EC2 userData #cloud-boothook or SageMaker lifecycle configs) that execute under the instance/notebook execution role, enabling credential exfiltration and misuse of privileged permissions; it cites proof-of-concept code, CloudTrail detection patterns (Stop → Modify → Start), and recommends restricting config-modification permissions, using SCPs and approval workflows to mitigate the risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.