Climbing the permission graph

There is no kernel to exploit here and no forgotten SUID binary to find. Escalation inside a cloud account is a graph problem: which identity may edit a policy, which may hand a role to a service that runs code on its behalf, and which may assume its way into an account it was never listed in. The permissions that make it work are almost always the ones granted so a team could manage its own resources without raising a ticket.