IAM role with administrator privileges can be assumed by a third party

Description

An IAM role with administrator privileges can be assumed by a third party. This configuration allows an external AWS account to assume a role with full administrative access to your AWS environment. The third party, or an attacker who compromises the third-party account, can assume this role and gain unrestricted control over all AWS resources, including the ability to create or delete resources, modify security configurations, and access sensitive data.

Remediation

  1. Review and manage IAM roles to ensure only trusted accounts can assume the role, and require external ID for third-party access.
  2. Apply IAM security best practices to follow the principle of least privilege and remove unnecessary administrative permissions.