AWS Execution Roles Enable Subtle Privilege Escalation in SageMaker and EC2
ID: 75f7bba9-0f8d-5097-bbf4-c5e4209bf290
STIX ID: report--75f7bba9-0f8d-5097-bbf4-c5e4209bf290
Feed Name: cybersecurityNews.com
This report details a persistent privilege-escalation technique against AWS compute services where attackers who can stop/start instances or notebooks and modify boot or lifecycle configurations inject scripts (via EC2 userData #cloud-boothook or SageMaker lifecycle configs) that execute under the instance/notebook execution role, enabling credential exfiltration and misuse of privileged permissions; it cites proof-of-concept code, CloudTrail detection patterns (Stop → Modify → Start), and recommends restricting config-modification permissions, using SCPs and approval workflows to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
