Vertical and horizontal
Vertical escalation means gaining more powerful rights, such as becoming a local or domain administrator, or root on a server. Horizontal escalation means accessing another user's account or data with the same level of rights, for example reading another customer's records in a web application. Both are common findings in penetration tests.
Common causes
Unpatched vulnerabilities in operating systems and software, services running with excessive rights, weak file or folder permissions, passwords stored in scripts or configuration files, users who are local administrators of their own laptops and, in the cloud, overly permissive roles and policies. MITRE ATT&CK documents the techniques in detail.
Prevention
Apply least privilege and remove local administrator rights from everyday users. Use privileged access management for administrator accounts. Keep systems patched through vulnerability management, apply hardening baselines and review cloud permissions regularly.
Detection
Alerts on new administrators, changes to privileged groups, unusual use of administrative tools and new services or scheduled tasks help reveal escalation attempts. Regular access reviews catch rights that have accumulated over time.




