CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisMedium
A vulnerability report lists a CVSS v3.1 vector segment of PR:H for a critical finding. During a risk-prioritization meeting, a client asks what this metric value means for exploitability. Which explanation is correct?
- AThe attacker must already possess administrative-level privileges on the vulnerable component before the attack can succeed
- BThe attacker can only exploit the vulnerability from an adjacent network segment
- CThe attacker must trick a victim user into performing an action to trigger the exploit
- DThe attacker requires no authentication to exploit the vulnerability
Show answer & explanationAnswer & explanation
Correct answer: A. The attacker must already possess administrative-level privileges on the vulnerable component before the attack can succeed
Privileges Required (PR) describes the level of access an attacker must have before exploiting the vulnerability. A value of H (High) means the attacker needs significant, often administrative, privileges on the component, which typically lowers real-world risk compared to PR:N (none required).
Why the other options are wrong
- B. This describes the Attack Vector (AV) metric, not Privileges Required.
- C. This describes the User Interaction (UI) metric, not Privileges Required.
- D. This describes PR:N (None), not PR:H.
CVSS Privileges Required (PR)
A CVSS v3.1 base metric indicating the level of access an attacker must have before exploiting a vulnerability: None, Low, or High.
- PR:N = no privileges needed (higher risk)
- PR:L = basic user-level privileges needed
- PR:H = admin-level privileges needed (lower practical risk)
Memory trick: PR checks the 'Pass' you need at the door before you can attack