Skip to content

Privilege Escalation

What is Privilege Escalation?

The act of exploiting a vulnerability, design flaw, or configuration oversight to gain elevated access to resources that are normally protected from an application or user. Can be vertical (gaining higher privileges) or horizontal (accessing other users' resources).

Information Security

Each of these is named in at least one of the same controls as privilege escalation. The number is how many controls name both.

What the standards actually require on privilege escalation

Requirements naming privilege escalation across 6 standards, quoted from the control text.

HKMA C-RAF iCAST (Intelligence-led Cyber Attack Simulation Testing) - mandatory for HIGH inherent risk AIs + optional for medium tier + modeled on UK CBEST + ECB TIBER-EU (verified separately in this corpus) + intelligence-led red team testing methodology.

HKMA-CRAF-iCAST-RedTeam-PurpleTeam-IntelLed · HKMA C-RAF iCAST (Intelligence-Led Cyber Attack Simulation Testing) for HIGH Inherent Risk AIs

UR E27 requires equipment manufacturers to deliver CBS with logging + forensic readiness capabilities aligned with IEC 62443-4-2 CR 2.8-2.12 (Auditable events) + FR 6 (Timely Response to Events).

IACS-UR-E27-Logging-Forensics-EventCapture · IACS UR E27 - Equipment Logging + Forensic Readiness + Event Capture + Tamper Detection

Disclose and operate authentication and authorization features per MDS2 PAUT + NAUT + AUTH sections. Person Authentication (PAUT) including user identification + password complexity + MFA support + biometric authentication + smart-card support + LDAP/Active Di...

MDS2-Person-Node-Authentication-Authorization-Auto-Logoff-AUTH-PAUT-NAUT · MDS2 Authentication + Authorization + Auto Logoff + PAUT + NAUT + AUTH + Identity Management
MITRE ATT&CK1 control

Apply the 14 Enterprise Tactics representing the adversary tactical goals during cyberattack phases (kill chain). TA0043 Reconnaissance - gathering information for planning future operations.

MITRE-ATTACK-Tactics-14-Enterprise-Kill-Chain-Reconnaissance-Initial-Access-Discovery-Lateral-Movement-Impact · MITRE ATT&CK 14 Enterprise Tactics + Reconnaissance + Initial Access + Discovery + Lateral Movement + Impact

Apply Section 5 target vulnerability validation including: password cracking (offline against captured hashes per RoE + John the Ripper + Hashcat + dictionary attacks + rainbow tables) + penetration testing (Sections 5.2 + 5.3 covering planning + discovery + a...

NISTSP115-4 · Target Vulnerability Validation - Password Cracking, Pen Testing, Social Engineering

Questions people ask about privilege escalation

What is Privilege Escalation?
The act of exploiting a vulnerability, design flaw, or configuration oversight to gain elevated access to resources that are normally protected from an application or user. Can be vertical (gaining higher privileges) or horizontal (accessing other users' resources).
Why is Privilege Escalation important for compliance?
Privilege Escalation is a key concept in Information Security. Understanding privilege escalation helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Privilege Escalation?
Privilege Escalation appears in the requirement text of HKMA Cyber Resilience Assessment Framework (C-RAF), IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems, ITU-T X.805 - Security Architecture for End-to-End Communications, MDS2 (Medical Device), MITRE ATT&CK. Across these standards we have identified 6 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Privilege Escalation?
Explore our compliance framework pages to see how privilege escalation applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Privilege Escalation applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.