CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium

An analyst reviews the CVSS v3.1 vector for a vulnerability in an internal HR application: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H. Based on the Privileges Required (PR) metric, what must be true for successful exploitation?

  1. ANo account or credentials are needed to exploit the flaw
  2. BThe attacker must have physical access to the server
  3. CA victim user must click a malicious link
  4. DThe attacker must already hold administrative (high-level) privileges on the vulnerable component
Show answer & explanation

Correct answer: D. The attacker must already hold administrative (high-level) privileges on the vulnerable component

PR:H indicates the attacker needs high (administrative-level) privileges on the target system before the vulnerability can be exploited, which lowers the base score compared to PR:N.

Why the other options are wrong

  • A. That describes PR:N, not PR:H.
  • B. Physical access relates to the Attack Vector (AV) metric, not PR.
  • C. That describes the User Interaction (UI) metric, not Privileges Required.

CVSS Privileges Required (PR)

A CVSS Base metric describing the level of privileges an attacker must possess before successfully exploiting a vulnerability.

  • Values: None (N), Low (L), High (H)
  • PR:N raises severity; PR:H lowers it
  • Independent of Attack Vector and User Interaction

Memory trick: AV-AC-PR-UI: Access, Complexity, Privileges, User clicks.

More Vulnerability Management questions