Published Tue, Feb 14th, 2023
Platforms
A privilege escalation vulnerability in Amazon EC2 Autoscaling was identified. The CreateLaunchConfiguration action lacked PassRole validation, allowing users to launch EC2 instances with unauthorized roles. AWS fixed the issue for both CreateLaunchConfiguration and CreateAutoScalingGroup actions, implementing proper PassRole validation when using the instance-id option.
Amazon EC2 Autoscaling
None required. AWS has deployed fixes worldwide for both affected actions.
No tracked CVEs
Contributed by https://github.com/ramimac
Entry Status
Finalized
Disclosure Date
Thu, Aug 11th, 2022
Exploitability Period
Until 2022/09/09
Known ITW Exploitation
-
Detection Methods
Monitor for unexpected EC2 instance launches or unusual role assignments in Autoscaling groups. Review CloudTrail logs for suspicious CreateLaunchConfiguration or CreateAutoScalingGroup API calls.
Piercing Index Rating
-
Discovered by
Shubham Agrawal, FINRA