CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisMedium

A vulnerability report lists a CVSS v3.1 vector segment of PR:H for a critical finding. During a risk-prioritization meeting, a client asks what this metric value means for exploitability. Which explanation is correct?

  1. AThe attacker must already possess administrative-level privileges on the vulnerable component before the attack can succeed
  2. BThe attacker can only exploit the vulnerability from an adjacent network segment
  3. CThe attacker must trick a victim user into performing an action to trigger the exploit
  4. DThe attacker requires no authentication to exploit the vulnerability
Show answer & explanation

Correct answer: A. The attacker must already possess administrative-level privileges on the vulnerable component before the attack can succeed

Privileges Required (PR) describes the level of access an attacker must have before exploiting the vulnerability. A value of H (High) means the attacker needs significant, often administrative, privileges on the component, which typically lowers real-world risk compared to PR:N (none required).

Why the other options are wrong

  • B. This describes the Attack Vector (AV) metric, not Privileges Required.
  • C. This describes the User Interaction (UI) metric, not Privileges Required.
  • D. This describes PR:N (None), not PR:H.

CVSS Privileges Required (PR)

A CVSS v3.1 base metric indicating the level of access an attacker must have before exploiting a vulnerability: None, Low, or High.

  • PR:N = no privileges needed (higher risk)
  • PR:L = basic user-level privileges needed
  • PR:H = admin-level privileges needed (lower practical risk)

Memory trick: PR checks the 'Pass' you need at the door before you can attack

More Vulnerability Discovery and Analysis questions