AWS - Directory Services Privesc
Directory Services
For more info about directory services check:
pageAWS - Directory Services / WorkDocs Enumds:ResetUserPassword
ds:ResetUserPassword
This permission allows to change the password of any existent user in the Active Directory. By default, the only existent user is Admin.
AWS Management Console
It's possible to enable an application access URL that users from AD can access to login:
And then grant them an AWS IAM role for when they login, this way an AD user/group will have access over AWS management console:
There isn't apparently any way to enable the application access URL, the AWS Management Console and grant permission
Last updated