CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium
An analyst reviews the CVSS v3.1 vector for a vulnerability in an internal HR application: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H. Based on the Privileges Required (PR) metric, what must be true for successful exploitation?
- ANo account or credentials are needed to exploit the flaw
- BThe attacker must have physical access to the server
- CA victim user must click a malicious link
- DThe attacker must already hold administrative (high-level) privileges on the vulnerable component
Show answer & explanationAnswer & explanation
Correct answer: D. The attacker must already hold administrative (high-level) privileges on the vulnerable component
PR:H indicates the attacker needs high (administrative-level) privileges on the target system before the vulnerability can be exploited, which lowers the base score compared to PR:N.
Why the other options are wrong
- A. That describes PR:N, not PR:H.
- B. Physical access relates to the Attack Vector (AV) metric, not PR.
- C. That describes the User Interaction (UI) metric, not Privileges Required.
CVSS Privileges Required (PR)
A CVSS Base metric describing the level of privileges an attacker must possess before successfully exploiting a vulnerability.
- Values: None (N), Low (L), High (H)
- PR:N raises severity; PR:H lowers it
- Independent of Attack Vector and User Interaction
Memory trick: AV-AC-PR-UI: Access, Complexity, Privileges, User clicks.