EN - FR - DE - ES - IT - PT -

LexiconDream

⬆️ Privilege Escalation

Gaining higher access rights than originally granted.

Privilege Escalation

Privilege escalation means gaining more access than you were given. An attacker starts with a low-privilege account, maybe a standard user or a compromised service. From there, they find a way to become administrator or root. That higher privilege lets them disable security tools, install backdoors, and reach data that was previously off-limits. Escalation is often the step that turns a minor compromise into a serious breach.

Escalation comes in two forms. Vertical escalation moves up the privilege ladder, from user to admin. Horizontal escalation moves sideways, from one user account to another with similar rights. Both matter. An attacker who compromises a help desk account and escalates horizontally to a finance account can approve payments. The techniques range from exploiting unpatched kernel vulnerabilities to finding credentials in configuration files or memory. Misconfigured services running as SYSTEM are a common path. So are scheduled tasks, weak service permissions, and stored credentials in scripts. Once an attacker has admin rights, detection gets harder. They can disable logging, clear event logs, and install rootkits. The earlier escalation is caught, the better.

Common escalation paths

Least privilege limits how much an attacker can do before escalating. Patching closes the vulnerabilities they need to escalate.

Comments

No comments yet. Be the first to share a thought.

Leave a comment