EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesEasy
A red team operator has successfully exploited a vulnerable service on a Windows server and obtained a low-privileged shell. To elevate their privileges to 'SYSTEM', they attempt to exploit a known kernel vulnerability. Which system hacking technique are they primarily employing?
- ALateral Movement
- BPrivilege Escalation
- CPersistence
- DClearing Logs
Show answer & explanationAnswer & explanation
Correct answer: B. Privilege Escalation
The goal of moving from a low-privileged shell to 'SYSTEM' access by exploiting a kernel vulnerability directly aligns with the definition of privilege escalation.
Why the other options are wrong
- A. Lateral Movement involves moving between different systems within a network, not elevating privileges on the same system.
- C. Persistence involves establishing continued access to a system, not necessarily elevating privileges.
- D. Clearing Logs is about removing evidence, a post-exploitation activity.
Privilege Escalation
Privilege escalation is the act of exploiting a bug, design flaw, or configuration oversight in an operating system or application to gain elevated access to resources that are normally protected from an application or user.
- Can be vertical (to higher privileges) or horizontal (to another user's privileges).
- Often involves exploiting kernel vulnerabilities, misconfigurations, or unpatched software.
- A critical step after initial compromise to gain full control.
Memory trick: Elevate, control, move, hide!