Cybersecurity glossary
What is Privilege Escalation?
Learn what privilege escalation is, how attackers move from limited access to admin control, the difference between vertical and horizontal escalation, and which controls stop it.
Definition
Privilege escalation is the process by which an attacker increases their access rights beyond what was initially granted—either by obtaining higher privileges (vertical) or accessing another user’s resources at the same privilege tier (horizontal).
Why privilege escalation matters
Initial access is rarely the end goal. A phished mailbox, a low-privilege web user, or a container foothold becomes catastrophic when attackers escalate privileges to administrators, other tenants, or domain controllers.
Privilege escalation is the hinge between “annoying incident” and “business-wide compromise.” Defense in depth aims to stop that hinge from swinging.
Vertical vs horizontal escalation
| Type | Meaning | Example |
|---|---|---|
| Vertical | Gain a higher privilege role | Standard user triggers an admin-only API successfully |
| Horizontal | Access another principal’s resources at similar privilege | User A reads User B’s invoices by changing an ID |
Common escalation paths
Broken access control
Missing role checks, IDOR, and function-level authorization flaws in apps/APIs.
Identity misconfiguration
Overbroad cloud IAM roles, group nesting, and standing admin privileges.
Local OS exploits
Kernel or service vulnerabilities that elevate a local user to SYSTEM/root.
Token and session abuse
Stolen admin cookies, JWTs with editable roles, or impersonation APIs.
How escalation fits an attack chain
Gain limited access
Phishing, vulnerable app, exposed service, or stolen low-privilege credentials.
Enumerate privileges
Discover roles, sudo rights, IAM policies, and reachable admin functions.
Exploit a boundary flaw
Use an access-control bug, misconfig, or local vulnerability to cross a trust boundary.
Obtain higher context
Admin session, root shell, or cross-tenant token is acquired.
Entrench and expand
Create backdoor users, steal secrets, move laterally, deploy ransomware.
Defenders respond
Revoke privileges, patch, reset credentials, and rebuild trust boundaries.
Prevention checklist
- Authorize every sensitive action server-side with explicit role and object checks.
- Apply least privilege in cloud IAM, databases, Kubernetes, and OS local rights.
- Remove standing admin; use just-in-time elevation with MFA and auditing.
- Patch known local privilege escalation CVEs quickly on endpoints and servers.
- Separate admin interfaces and require stronger authentication for them.
- Test horizontal access with two users in automated suites.
- Monitor privilege changes, new admin creations, and unusual sudo/IAM activity.
- Assume breach of low-privilege accounts and design containment accordingly.
The practical takeaway
Privilege escalation turns limited access into powerful access—vertically to higher roles or horizontally across users/tenants. It is a core stage in real intrusions.
Enforce authorization everywhere, keep privileges minimal, patch escalation bugs fast, and watch privileged operations closely. Stopping escalation often stops the breach from becoming existential.
Related security terms
Insecure Direct Object Reference (IDOR)
A common horizontal escalation pattern via object ID tampering.
Broken Authentication
Identity flaws that often provide the initial foothold before escalation.
Exploit Chain
Privilege escalation is frequently a middle link in multi-step intrusions.
Role-Based Access Control (RBAC)
An authorization model that must be enforced correctly to prevent escalation.
Frequently asked questions
What is privilege escalation in simple terms?
Privilege escalation is when someone starts with limited access and finds a way to get more powerful access—like a normal user becoming an admin, or reading another customer’s data.
What is vertical vs horizontal privilege escalation?
Vertical means gaining a higher role (user to admin). Horizontal means accessing another account’s data while staying at a similar role level.
Is IDOR a type of privilege escalation?
IDOR is a common horizontal privilege escalation technique when object-level authorization is missing.
Do only operating systems have privilege escalation?
No. Web apps, APIs, cloud IAM, containers, and databases all have privilege boundaries that can be crossed improperly.
How do attackers escalate privileges?
Through access-control bugs, misconfigured roles, sudo/capabilities abuse, vulnerable services, stolen admin tokens, and chaining lower-severity flaws.
How can organizations prevent privilege escalation?
Enforce authorization on every action, apply least privilege, patch local escalations quickly, separate admin paths, and monitor privileged activity.
Why is privilege escalation so important in ransomware incidents?
Attackers often need higher privileges to disable defenses, access backups, and deploy encryption widely across an environment.
References
Explore authoritative guidance and frameworks related to privilege escalation.
Explore every security definition
Return to the glossary to search by term, alias, starting letter, or security category.