CYBERSECURITY

Privilege escalation

Attackers gaining more access than an account was given, and how to limit it.

Privilege escalation is a way an attacker gets more access than the account was supposed to have. Recent cases include vulnerabilities in platforms such as Google Vertex AI, and a case where an attacker used a large language model’s weaknesses to reach sensitive data. The same pattern lets an outsider impersonate a trusted user, or lets an insider open data they are not allowed to see.

Two kinds

  • Vertical. The attacker moves to a higher role, such as from a standard account to an administrator.
  • Horizontal. The attacker stays at the same level and opens another person’s resources or account.

With that access, they can steal data, turn security off, or do wider damage.

How common it was in 2023

In 2023, privilege escalation accounted for 12.1 percent of reported vulnerabilities in the CISA Known Exploited Vulnerabilities catalog. That made it the most common type in that catalog that year. When it succeeds, attackers can take data out, change important applications, or shut operations down.

What to do

  • Least privilege. Give each person and each application only the access the job needs. Do not hand out administrator rights unless the work requires them.
  • Audit permissions, and remove access that is old or broader than the role.
  • Read access logs, and use monitoring that flags activity that does not fit.
  • Patch promptly. Old software is where attackers look for known holes.
  • Use multi-factor authentication so a stolen password is harder to use.

Permissions, monitoring, and these practices reduce the risk. The point of the work is both the business and the trust of customers.

Back to the blog