GlossaryAttack surface and pentesting

Privilege escalation

Short answer

Privilege escalation is when an attacker, or a user, gains higher permissions than they were given, for example moving from a standard account to administrator. It usually exploits unpatched vulnerabilities, misconfigurations or exposed credentials, and it is a key step in most serious attacks.

Vertical and horizontal

Vertical escalation means gaining more powerful rights, such as becoming a local or domain administrator, or root on a server. Horizontal escalation means accessing another user's account or data with the same level of rights, for example reading another customer's records in a web application. Both are common findings in penetration tests.

Common causes

Unpatched vulnerabilities in operating systems and software, services running with excessive rights, weak file or folder permissions, passwords stored in scripts or configuration files, users who are local administrators of their own laptops and, in the cloud, overly permissive roles and policies. MITRE ATT&CK documents the techniques in detail.

Prevention

Apply least privilege and remove local administrator rights from everyday users. Use privileged access management for administrator accounts. Keep systems patched through vulnerability management, apply hardening baselines and review cloud permissions regularly.

Detection

Alerts on new administrators, changes to privileged groups, unusual use of administrative tools and new services or scheduled tasks help reveal escalation attempts. Regular access reviews catch rights that have accumulated over time.

Related terms

Keep reading on this topic

External and internal attack surface management, cloud configuration and application security: finding exposures and prioritising them by real risk.

Go to the topic hub