What is the typical aim of local privilege escalation exploits?

Study for the SANS560 GIAC Penetration Tester (GPEN) Test. Study with flashcards and multiple choice questions, each question has hints and explanations. Get ready for your exam!

Multiple Choice

What is the typical aim of local privilege escalation exploits?

Explanation:
Local privilege escalation aims to raise the attacker's privilege level on the compromised host. An attacker already on the system uses weaknesses, misconfigurations, or insecure components to move from a regular user to an elevated account (like root or administrator). With higher privileges, they can access protected files, modify security settings, install or hide tools, and perform actions that require admin rights, which is the defining goal of LPE. Denying service describes a disruption of availability, not privilege gain. Exfiltrating data focuses on stealing information, which may happen with various access levels but isn’t the primary target of privilege escalation. Rebooting the system isn’t the typical aim of LPE either; the goal is to obtain more control, not simply restart the machine.

Local privilege escalation aims to raise the attacker's privilege level on the compromised host. An attacker already on the system uses weaknesses, misconfigurations, or insecure components to move from a regular user to an elevated account (like root or administrator). With higher privileges, they can access protected files, modify security settings, install or hide tools, and perform actions that require admin rights, which is the defining goal of LPE.

Denying service describes a disruption of availability, not privilege gain. Exfiltrating data focuses on stealing information, which may happen with various access levels but isn’t the primary target of privilege escalation. Rebooting the system isn’t the typical aim of LPE either; the goal is to obtain more control, not simply restart the machine.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy