Skip to main content

Identity / IAM / Threats / DEV

IAM Role is Coerced into Unauthorized Cross-Account Actions (Confused Deputy)

CCC.IAM.TH12

An external actor tricks a legitimate, authorized third-party application into making requests to the cloud environment. A role in the cloud account (the "deputy"), which trusts that third-party application, then performs unauthorized actions on behalf of the actor.

Related Capabilities

IDTitleDescription
CCC.IAM.CP06IAM Roles / Service PrincipalsAbility to create, manage, list and delete IAM roles. IAM role is an identity for applications or services to access resources.
CCC.IAM.CP10Custom RolesAbility to create, manage, list and delete custom roles. Custom roles are user-defined roles that defines what actions are allowed.
CCC.IAM.CP15Role Assumption / DelegationAbility to temporarily assume another role or delegate access. Commonly used for user impersonation or temporary privilege elevation.

External Mappings

FrameworkIDRemarks
MITRE-ATT&CKT1199Trusted Relationship
MITRE-ATT&CKT1548.005Abuse Elevation Control Mechanism: Temporary Elevated Cloud Access