{"id":5304,"date":"2025-07-12T10:01:39","date_gmt":"2025-07-12T10:01:39","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/12\/aws-organizations-mis-scoped-managed-policy-let-hackers-to-take-full-aws-organization-control\/"},"modified":"2025-07-12T10:01:39","modified_gmt":"2025-07-12T10:01:39","slug":"aws-organizations-mis-scoped-managed-policy-let-hackers-to-take-full-aws-organization-control","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/12\/aws-organizations-mis-scoped-managed-policy-let-hackers-to-take-full-aws-organization-control\/","title":{"rendered":"AWS Organizations Mis-scoped Managed Policy Let Hackers To Take Full AWS Organization Control"},"content":{"rendered":"<p>    AWS Organizations Mis-scoped Managed Policy Let Hackers To Take Full AWS Organization Control<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical security vulnerability in AWS Organizations has been discovered that could allow attackers to achieve complete control over entire multi-account AWS environments through a mis-scoped managed policy.<\/p>\n<p>The flaw, identified in the AmazonGuardDutyFullAccess managed policy version 1, enables privilege escalation from a compromised member account to full organizational takeover, including potential control of the management account itself.<\/p>\n<p>The vulnerability stems from an improperly scoped permission within the AWS-managed policy that grants the <code>organizations:RegisterDelegatedAdministrator<\/code> action with unrestricted resource access.<\/p>\n<p>This oversight allows attackers who compromise a user or role in the management account with the vulnerable policy attached to register any account within the organization as a delegated administrator for sensitive services, effectively bypassing intended security boundaries.<\/p>\n<p>The attack vector leverages AWS Organizations\u2019 delegated administrator feature, which was designed to reduce reliance on highly privileged management accounts by allowing specific member accounts to administer services organization-wide.<\/p>\n<p>However, the mis-scoped policy transforms this security feature into a powerful <a href=\"https:\/\/cybersecuritynews.com\/ms-patch-rce-privilege-escalation\/\" target=\"_blank\" rel=\"noreferrer noopener\">escalation mechanism<\/a>.<\/p>\n<p>An attacker can chain delegation privileges with control over a member account to gain administrative access to critical services such as AWS Identity and Access Management Identity Center (formerly SSO) or CloudFormation StackSets across all organizational accounts.<\/p>\n<p>Cymulate researchers <a href=\"https:\/\/cymulate.com\/blog\/aws-delegated-admin-org-takeover\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this vulnerability during their investigation of AWS Organizations cross-account pivoting and compromise scenarios.<\/p>\n<p>The research team, led by Ben Zamir, discovered that the policy\u2019s overly permissive structure could enable attackers to delegate sensitive services to accounts under their control, subsequently manipulating organization-wide identity management or deploying malicious infrastructure across the entire environment.<\/p>\n<p>The technical exploitation process involves several critical steps that demonstrate the severity of this vulnerability.<\/p>\n<p>Once an attacker compromises a management account identity with the vulnerable policy, they can execute the following command to register a controlled account as a delegated administrator:-<\/p>\n<pre class=\"wp-block-code\"><code>aws organizations register-delegated-administrator --account-id  --service-principal <\/code><\/pre>\n<h2 class=\"wp-block-heading\"><strong>Persistence and Privilege Escalation Mechanism<\/strong><\/h2>\n<p>The most concerning aspect of this vulnerability lies in its ability to establish <a href=\"https:\/\/cybersecuritynews.com\/using-threat-intelligence-to-combat-advanced-persistent-threats-apts\/\" target=\"_blank\" rel=\"noreferrer noopener\">persistent<\/a>, organization-wide access through legitimate AWS features.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjLyo3O0SPar91y6-dDo5vnvIM9MvPXNI8TlA5F9LPN8VVCin0YcUafhof24V7Awl5fbLrV8WW05DH6JZhoMzSN6A8g0F-8wqL_CAhke0h2rW6GSG1NlVdwiURYPzg_C3A4iqjV5pvso-20faKQ0tiPhiF1cc6XHa6XgwdfaICQbGEcKywlkabCqQlaT00\/s16000\/Persistence%2520and%2520Privilege%2520Escalation%2520%28Source%2520-%2520Cymulate%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Persistence and Privilege Escalation (Source \u2013 Cymulate)<\/figcaption><\/figure>\n<\/div>\n<p>When an attacker successfully registers a compromised account as a delegated administrator for AWS Identity Center, they gain the ability to manipulate permission sets, user groups, and access configurations across all organizational accounts.<\/p>\n<p>This capability allows them to add malicious identities to <a href=\"https:\/\/cybersecuritynews.com\/microsoft-enhance-microsoft-365-security\/\" target=\"_blank\" rel=\"noreferrer noopener\">high-privilege<\/a> groups or reset passwords of users with administrative access to the management account.<\/p>\n<p>The persistence mechanism is particularly insidious because it operates through legitimate delegation channels that may not trigger traditional security alerts.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhvTNbGEf9r7PG2apdWniri84fK1KdittBMC-CCzlohhisgLuDIzyo5tD4llTMHbiR4wCya8ZQkh3yIUXhLx0qpXHFdOFqIR4AqMtoF_csCSeNAQxEXEqvhrfZWloHNAynLlSRPujaVPNs9OQbOCeHQcpaQYU180VkPnzmX7lAZlQqPISidmhlavW1TID4\/s16000\/Attack%2520flow%2520%28Source%2520-%2520Cymulate%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Attack flow (Source \u2013 Cymulate)<\/figcaption><\/figure>\n<\/div>\n<p>Attackers can modify existing permission sets or create new ones with elevated privileges, ensuring continued access even if the initial compromise vector is discovered and remediated.<\/p>\n<p>Additionally, the read-only organizational access granted to delegated administrators provides complete visibility into the environment structure, enabling attackers to identify high-value targets and plan sophisticated <a href=\"https:\/\/cybersecuritynews.com\/information-security-threats-for-business\/\" target=\"_blank\" rel=\"noreferrer noopener\">multi-account attacks<\/a>.<\/p>\n<p>AWS has responded to this discovery by releasing version 2 of the AmazonGuardDutyFullAccess managed policy with stricter resource constraints that eliminate the escalation path.<\/p>\n<p>However, existing roles and users attached to version 1 remain vulnerable until administrators manually upgrade to the corrected policy.<\/p>\n<p>Organizations should immediately audit all principals using the vulnerable policy and implement the updated version to prevent potential exploitation of this critical security flaw.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\">Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -&gt;\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=braodo_stealer&amp;utm_content=demo_1&amp;utm_term=250625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Try ANY.RUN now<\/strong><\/a><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/aws-organizations-mis-scoped-managed-policy\/\">AWS Organizations Mis-scoped Managed Policy Let Hackers To Take Full AWS Organization Control<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/aws-organizations-mis-scoped-managed-policy\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>AWS Organizations Mis-scoped Managed Policy Let Hackers To Take Full AWS Organization Control A critical security vulnerability in AWS Organizations has been discovered that could allow attackers to achieve complete control over entire multi-account AWS environments through a mis-scoped managed policy. The flaw, identified in the AmazonGuardDutyFullAccess managed policy version 1, enables privilege escalation from [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-5304","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5304"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5304"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5304\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5304"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5304"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5304"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}