Privilege Escalation
Privilege escalation is the attempt by an attacker who already holds some level of access to widen their rights in order to move through the network. Escalation is rarely the first stage — it comes after entry through, say, an ordinary user account or a compromised service. It takes the attacker from the crack they slipped through to control of the whole system. There are two directions: vertical escalation, from an ordinary user to domain administrator, and horizontal, moving from one account to another user's resources at the same level of rights.
Term
description · examples · notesPrivilege escalation is the attempt by an attacker who already holds some level of access to widen their rights in order to move through the network. Escalation is rarely the first stage — it comes after entry through, say, an ordinary user account or a compromised service. It takes the attacker from the crack they slipped through to control of the whole system. There are two directions: vertical escalation, from an ordinary user to domain administrator, and horizontal, moving from one account to another user's resources at the same level of rights.
Description
The way up is found wherever the protection gives way. Most often it is vulnerabilities in the operating system or in software, wrong configurations, overly broad file permissions, and services running with more rights than they need. Leftover credentials and forgotten administrator accounts are frequent prizes. Each of those mistakes is a shortcut from a lower level of authority to a higher one.
The defense is built on least privilege: every account and every service gets exactly the rights the work requires, not a crumb more. With it go regular updates that close known vulnerabilities, hardened configurations, separate handling of administrator accounts, and monitoring of privileged actions. The point is to limit the reach of the break-in — if an account has limited rights, an attacker holding it has limited effect.
Examples
- Exploiting a vulnerability in the operating system kernel to go from an ordinary user account to full control of the machine.
- Abusing a misconfigured application that runs under the SYSTEM account, where the attacker inherits the rights of the corrupted service.
- Editing a service startup script which, through a mistake in the permissions, an unprivileged user can also change.
Notes
- Escalation is the attacker's magic potion — every account taken brings them closer to full control of the network, which is why the compromise of an ordinary user account is not a case to underestimate.
- A least-privilege policy is the most effective defense: what an account cannot do, an attacker cannot do either.
Mentioned in the news
- 6. JUL 2026. Propust u srcu Linuxa daje root svima →
- 30. MAJ 2026. Telekinezom do domen kontrolera: udaljeno i bez ovlašćenja do srca poslovne mreže →
- 18. MAJ 2026. Mythos Preview pomogao u izradi macOS kernel exploita za Apple M5 →
- 1. MAJ 2026. Nessus Agent ranjivost na Windowsu omogućava izvršavanje koda kao SYSTEM →
- 28. APR 2026. Pack2TheRoot ranjivost u Linux PackageKit-u vodi do root pristupa →
- 28. APR 2026. Microsoft zakrpio Entra ID ulogu koja je mogla da proširi privilegije →
- 22. APR 2026. Microsoft zakrpio kritičan ASP.NET Core propust za podizanje privilegija →
- 16. APR 2026. Objavljen PoC za Microsoft Defender ranjivost CVE-2026-33825 →
- 15. APR 2026. GPUBreach pokazuje da GPU Rowhammer može da vodi do potpunog preuzimanja sistema →
- 28. MAR 2026. Ranjivost u IDrive klijentu za Windows omogućava podizanje privilegija do SYSTEM nivoa →
- 13. MAR 2026. CrackArmor ranjivosti u Linux AppArmor omogućavaju eskalaciju privilegija na root →
- 11. MAR 2026. Kritične ranjivosti u SAP sistemima omogućavaju eskalaciju privilegija →
- 11. MAR 2026. Ranjivost u Active Directory Domain Services omogućava eskalaciju privilegija →
- 24. FEB 2026. Kritične ranjivosti u SolarWinds Serv-U omogućavaju root pristup serverima →
- 6. JUN 2026. Planeta Odmetnik pristupa SYSTEM nalogu kroz Windows Defender →
- 22. MAJ 2026. Zero-day u Microsoft Defenderu: Napadač navodi ugrađeni antivirus da mu otključa SYSTEM →
- 19. APR 2026. Tri Microsoft Defender zero-day ranjivosti aktivno zloupotrebljene →
Techniques
carried out with 8Techniques used to carry it out. Select one to open its page.
Defenses
countered by 4How it is defended against. Select one to open its page.