EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesEasy

A red team operator has successfully exploited a vulnerable service on a Windows server and obtained a low-privileged shell. To elevate their privileges to 'SYSTEM', they attempt to exploit a known kernel vulnerability. Which system hacking technique are they primarily employing?

  1. ALateral Movement
  2. BPrivilege Escalation
  3. CPersistence
  4. DClearing Logs
Show answer & explanation

Correct answer: B. Privilege Escalation

The goal of moving from a low-privileged shell to 'SYSTEM' access by exploiting a kernel vulnerability directly aligns with the definition of privilege escalation.

Why the other options are wrong

  • A. Lateral Movement involves moving between different systems within a network, not elevating privileges on the same system.
  • C. Persistence involves establishing continued access to a system, not necessarily elevating privileges.
  • D. Clearing Logs is about removing evidence, a post-exploitation activity.

Privilege Escalation

Privilege escalation is the act of exploiting a bug, design flaw, or configuration oversight in an operating system or application to gain elevated access to resources that are normally protected from an application or user.

  • Can be vertical (to higher privileges) or horizontal (to another user's privileges).
  • Often involves exploiting kernel vulnerabilities, misconfigurations, or unpatched software.
  • A critical step after initial compromise to gain full control.

Memory trick: Elevate, control, move, hide!

More System Hacking Phases and Attack Techniques questions