- Cloud Native Applications
- Application Security
- Application Security
- Web Application Security
- Application Security Posture Management (ASPM)
- Microsegmentation
- Python Security
- SaaS Security
- Node.JS Security
- PHP Security
- AI in Cyber Security
- Cybersecurity for Financial Services
- The Principle of Least Privilege (PoLP)
- Identity and Access Management
- Cybersecurity in Banking
- Threat Detection and Response
- Cyber Kill Chain
- Threat Hunting
- Zero Trust Security
- Zero Trust Architecture
- Fileless Attacks
- DSPM
- Container Scanning
- Kubernetes
- Kubernetes
- Kubernetes Alternatives
- Kubernetes Namespace
- Kubernetes Architecture
- Kubernetes Cluster
- Kubernetes Nodes
- Kubernetes Pods
- Kubernetes Jobs
- Kubernetes Workloads
- Kubernetes Monitoring
- Kubernetes Security
- Kubernetes RBAC
- Secret Scanning
- Kubernetes Security Posture Management (KSPM)
- Kubernetes on AWS
- Kubernetes on VMware
- Kubernetes Vulnerability Scanning
- Managing Containers in Kubernetes
- K3s
- eBPF in Kubernetes
- Kubernetes Dashboard
- Kubernetes Operators
- Kubernetes Services
- Kubernetes Devops
- Kubernetes Networking
- Kubernetes ConfigMap
- Kubernetes Management
- Kubernetes Helm
- Kubernetes as a Service
- Kubernetes Serverless
- Kubernetes Tutorials
- Cloud Attacks
- Cloud Attacks
- Malware Attacks
- Zero Day Attack
- Top 10 Cyber Security Threats
- Arbitrary Code Execution
- Cryptojacking
- AI Attacks
- Prompt Injection
- Backdoor Attacks
- Reverse Shell Attack
- Remote Code Execution
- Defense Evasion
- Honeypots in Cybersecurity
- Malware Analysis
- AI Malware
- Lateral Movement
- Advanced Malware Protection
- CNAPP
- AI Security
- Container Platforms
- Containerized Architecture
- Containerized Architecture
- Docker Secrets
- Container Runtime Interface
- Container Images
- Image Scanning
- Container Compliance
- Docker Security Best Practices
- Container Security
- Container Security Best Practices
- Container Security Tools
- ECS Security
- Network Segmentation
- Istio security
- runC
- Service Mesh
- Image Repository
- Container Escape
- Container Runtime
- Docker Container
- OSS Container Image Scanning Tools
- What Is a Container?
- Docker Images
- Containerization 101
- VM vs. Container
- Containerization vs. Virtualization
- Containerized Applications
- Microservices and Containerization
- Registry Scanning
- Docker CVEs
- Docker Monitoring
- Securing Containers with Docker Scanning
- Docker CIS Benchmark
- Seccomp
- Docker Alpine
- Docker API
- Docker Tools
- 100 Best Docker Tutorials
- Docker Alternatives
- Docker Swarm
- Docker Containers vs. Virtual Machines (VMs)
- Docker Architecture
- Docker Networking
- Docker Registries
- Docker Orchestration
- OpenShift vs Docker
- Container Cloud Computing
- Container DevOps
- Docker in Production
- Container Monitoring
- Container Advantages
- Docker Hub
- Serverless Architecture
- Supply Chain Security
- Supply Chain Compliance
- SolarWinds Attack
- Supply Chain Security
- Secure Software Development Lifecycle
- Software Supply Chain Attacks
- Dependency Confusion Attack
- SLSA
- SSDF
- Software Composition Analysis
- Security Misconfigurations
- Repojacking
- Privilege Escalation
- CI/CD Security
- SAST Security
- GitLab Security
- GitHub Secret Scanning
- OWASP Dependency-Check
- Software Bill of Materials
- SBOM Tools
- NPM Vulnerabilities
- Log4j Vulnerability
- Text4Shell
- Secrets Management
- Jenkins Security
- Yarn vs. NPM
- Source Code Leaks
- Container Image Signing
- Open Source Licenses
- Vulnerability Management
- Vulnerability Management Tools
- Vulnerability Scanning Process
- Vulnerability Management
- Vulnerability Scanning
- Vulnerability Prioritization
- Open Source Vulnerability Scanning
- Vulnerability Remediation
- Vulnerability Scanner
- Risk-Based Vulnerability Management
- Vulnerability Exploitability eXchange (VEX)
- Malware Detection
- Fileless Malware
- Attack Vectors
- Malicious Code
- Risk Posture
- Alert Fatigue in Cybersecurity
- Cyber Security Posture
- MITRE ATT&CK
- MITRE ATT&CK Framework
- LLM Security
- Code Scanning
- Attack Surface
- Attack Surface Management
- What Are Indicators of Compromise (IoC)?
- Secure Code
- Configuration Drift
- Trivy
- DevSecOps
- DevSecOps
- DevSecOps Pipeline
- DevSecOps Best Practices
- DevSecOps vs SecDevOps
- Threat Modeling
- Mean Time to Repair (MTTR)
- eBPF Linux
- Cloud DevOps
- DevOps Tools
- GitOps vs DevOps
- Code Security
- Secure Code Review
- DevOps Security
- Infrastructure as Code (IaC) Security
- Infrastructure as Code DevOps
- Executive Order 14028 (U.S. Cybersecurity Executive Order)
- Open Source Security
- Shift-Left Security
- Shift Right Testing and Security
- What Is SecOps (Security Operations)?
- SecDevOps
- DevSecOps Tools
- Linux Security
- Rocky Linux
- Azure DevOps
- Cloud Security
- Cloud Security
- Cloud Security Challenges
- Cloud Security Tools
- Code to Cloud
- Cloud Protection
- Cloud Security Frameworks
- Cloud Security Standards
- Cloud Security Controls
- Cloud Security Posture Management (CSPM)
- AI Workloads
- Cloud Digital Forensics
- Cloud Computing Security Architecture
- What Is Enterprise Cloud Security?
- Virtualized Security
- CSPM Tools
- Vulnerabilities in Cloud Computing
- Top 7 Risks of Cloud Computing
- Cloud Security Assessment
- Cloud Visibility
- Cloud Governance
- Cloud Security Strategy
- Cloud Security Policy
- DFIR
- Cloud Workloads
- Public Cloud Security
- Private Cloud vs. Public Cloud
- Runtime Security
- Azure Cloud Security
- Azure Security Best Practices
- Azure Security vs. AWS Security
- AWS GovCloud: Basics & How It Compares to Azure & GCP
- S3 Security
- Cloud Misconfiguration
- Terraform Security
- Hybrid Cloud Security
- Multi-Cloud Strategy
- Agentless vs. Agent-Based Security & Monitoring
- Cloud Infrastructure Security
- Gartner CSPM
- Cloud Security Scanner
- AWS CIS Benchmark
- Cloud Configuration Management
- Cloud Workload Protection (CWP)
- Cloud Workload Protection Platforms (CWPP)
- Cloud Workload Security
- Cloud Vulnerabilities and Tools that Can Help
- Google Cloud Security
- Shared Responsibility Model
- AWS Shared Responsibility Model
- AWS Cloud Security
- Multi Cloud Security
- Cloud Compliance
- Kubernetes in Production
- Cloud Detection And Response
Privilege Escalation in Windows, Linux, and K8s and 6 Ways to Prevent It
Privilege escalation is a situation where a malicious actor gains unauthorized access to resources or privileges on a computer system, network, or application
Table of Contents
- What Is Privilege Escalation?
- Why Is It Important to Prevent Privilege Escalation?
- Horizontal Privilege Escalation vs. Vertical Privilege Escalation
- Linux Privilege Escalation Techniques
- Enumeration
- Kernel Exploits
- SUDO Right Exploitation
- Windows Privilege Escalation Techniques
- Access Token Manipulation
- Bypass User Account Control
- Privilege Escalation in Kubernetes
- Privilege Escalation from Node/Proxy Rights in Kubernetes RBAC
- Privilege Escalation with the CSR API
- 6 Ways to Prevent Privilege Escalation Attacks
- Keep Accounts up to Date With Comprehensive Privilege Account Management
- Patch and Update Software
- Perform Vulnerability Scans
- Monitor Network Traffic and Behavior
- Institute a Strong Password Policy
- Conduct Security Awareness Training
- Preventing Privilege Escalation Attacks with Aqua
What Is Privilege Escalation?
Privilege escalation refers to a situation where an attacker or malicious actor uses an existing account or permissions and manages to increase the level of permission to perform unauthorized actions. This can be done in a number of ways, including exploiting vulnerabilities in the system or application, using stolen credentials, or manipulating user permissions.
For example, an attacker may be able to gain access to a system with limited privileges as a regular user, but then use a privilege escalation attack to gain administrative privileges and access to more sensitive resources. This can allow the attacker to make changes to the system, access sensitive data, or install malicious software.
There are several methods that attackers can use to escalate privileges, including:
- Exploiting vulnerabilities: This involves finding and exploiting vulnerabilities in the system or application to gain higher privileges.
- Using stolen credentials: If an attacker can obtain the login credentials of a user with higher privileges, they can use those credentials to gain access to restricted resources.
- Manipulating user permissions: An attacker may try to manipulate user permissions or group membership to gain access to resources that they would not normally have access to.
Preventing privilege escalation is an important aspect of cybersecurity, and organizations can take several steps to protect against it, such as regularly updating software and applications, enforcing strong password policies, and monitoring for suspicious activity.
This is part of a series of articles about supply chain security.
In this article:
- Why Is It Important to Prevent Privilege Escalation?
- Horizontal Privilege Escalation vs. Vertical Privilege Escalation
- Linux Privilege Escalation Techniques
- Enumeration
- Kernel Exploits
- SUDO Right Exploitation
- Windows Privilege Escalation Techniques
- Access Token Manipulation
- Bypass User Account Control
- Privilege Escalation in Kubernetes
- Privilege Escalation from Node/Proxy Rights in Kubernetes RBAC
- Privilege Escalation with the CSR API
- 6 Ways to Prevent Privilege Escalation Attacks
- Keep Accounts up to Date With Comprehensive Privilege Account Management
- Patch and Update Software
- Perform Vulnerability Scans
- Monitor Network Traffic and Behavior
- Institute a Strong Password Policy
- Conduct Security Awareness Training
Why Is It Important to Prevent Privilege Escalation?
Preventing privilege escalation is important because it can help to protect against a wide range of attacks and prevent unauthorized access to sensitive resources. Some examples of attacks that may use privilege escalation include:
- Ransomware attacks: Ransomware is a type of malware that encrypts a victim’s files and demands payment to decrypt them. If an attacker is able to escalate their privileges, they may be able to install ransomware on a larger scale, potentially affecting the entire network.
- Data theft: An attacker with escalated privileges may be able to access and steal sensitive data, such as financial records or personally identifiable information.
- System modifications: An attacker with escalated privileges may be able to make changes to the system, such as deleting files or altering configuration settings.
- Persistent access: An attacker who is able to escalate their privileges may be able to maintain access to the system even if their initial access is discovered and blocked. This can allow them to continue to carry out attacks or gather sensitive information over a longer period of time.
Horizontal Privilege Escalation vs. Vertical Privilege Escalation
Horizontal privilege escalation and vertical privilege escalation are two different types of privilege escalation that refer to the scope of the privileges that an attacker is able to gain.
Horizontal privilege escalation occurs when an attacker gains access to resources or privileges that are within their existing scope of access. For example, an attacker who is a regular user on a system may be able to escalate their privileges to gain access to resources or functions that are normally available to regular users, but which they are not authorized to access. This might include access to sensitive files or the ability to make changes to the system.
Vertical privilege escalation, on the other hand, occurs when an attacker is able to gain access to resources or privileges that are outside their normal scope of access. This might involve an attacker who starts out with limited privileges, such as a regular user, gaining access to administrative privileges or the ability to make changes to the system.
Linux Privilege Escalation Techniques
Enumeration
Enumeration is a technique that involves gathering information about a system in order to identify vulnerabilities or weaknesses that can be exploited to gain unauthorized access. In the context of privilege escalation on a Linux system, enumeration might involve gathering information about installed software, user accounts, and system configurations to identify potential vulnerabilities or weaknesses that can be exploited to escalate privileges.
Kernel Exploits
Kernel exploits are vulnerabilities or weaknesses in the kernel of an operating system that can be exploited to gain unauthorized access to the system or to escalate privileges. The kernel is the core of the operating system and has access to all system resources, making it a valuable target for attackers.
SUDO Right Exploitation
SUDO right exploitation involves using the SUDO (superuser do) command to execute a command with superuser privileges, even if the user does not have those privileges. SUDO is typically used to allow users to perform tasks that require elevated privileges, such as installing software or making system-wide configuration changes. However, if an attacker is able to exploit a vulnerability in SUDO or manipulate the SUDO configuration, they may be able to gain unauthorized access to superuser privileges.
Windows Privilege Escalation Techniques
Access Token Manipulation
An access token is a data structure that is used to identify a user and determine their access rights on a Windows system. By manipulating the access token, an attacker may be able to gain access to resources or privileges that they would not normally have access to.
Bypass User Account Control
User Account Control (UAC) is a security feature in Windows that prompts the user for permission before allowing certain actions to be taken. Bypassing UAC can allow an attacker to execute a command or make changes to the system without the user’s knowledge or consent.
Privilege Escalation in Kubernetes
Kubernetes clusters are increasingly used to deploy many kinds of workloads, including sensitive and mission critical workloads. Privilege escalation in Kubernetes is an attractive way for attackers to gain unauthorized access to these workloads. Here are two examples of privilege escalation attacks in Kubernetes clusters, discovered by the Aqua Nautilus research team.
Privilege Escalation from Node/Proxy Rights in Kubernetes RBAC
In Kubernetes, privilege escalation from node/proxy rights refers to a situation where an attacker or malicious actor is able to gain unauthorized access to resources or privileges within the Kubernetes cluster by exploiting the rights granted to a node or proxy.
In Kubernetes, nodes are the machines (either virtual or physical) that run the Kubernetes system and host the containers. Proxies are intermediary components that are used to communicate with the Kubernetes API server and manage communication between the nodes and the API server.
Nodes and proxies are typically granted certain rights within the Kubernetes cluster, such as the ability to create and manage resources and access certain API endpoints. However, if an attacker is able to gain access to a node or proxy, they may be able to use those rights to escalate their privileges and gain unauthorized access to other resources within the cluster.
Privilege Escalation with the CSR API
The CSR API is an API in Kubernetes that is used to manage certificate signing requests (CSRs). CSRs are requests for a certificate authority (CA) to sign a certificate for a specific purpose, such as authenticating a user or device. The CSR API allows users to create, view, and approve CSRs.
If an attacker is able to exploit vulnerabilities in the CSR API, they may be able to gain unauthorized access to resources or privileges within the Kubernetes cluster. For example, an attacker may be able to create a CSR that is signed by the CA, allowing them to authenticate as a user or device and gain access to restricted resources.
6 Ways to Prevent Privilege Escalation Attacks
Keep Accounts up to Date With Comprehensive Privilege Account Management
Properly managing user accounts and privileges can help to prevent privilege escalation attacks by limiting the access that users have to sensitive resources and functions. This might include regularly reviewing and updating user accounts and privileges, enforcing strong passwords and authentication measures, and monitoring for suspicious activity.
Patch and Update Software
Regularly patching and updating software and applications can help to prevent privilege escalation attacks by addressing known vulnerabilities and closing potential entry points for attackers. This includes keeping the operating system and any associated applications up to date with the latest patches and updates.
Perform Vulnerability Scans
Regularly scanning the system for vulnerabilities can help to identify potential weaknesses that could be exploited in a privilege escalation attack. This might include using tools and techniques to scan for vulnerabilities in the operating system, applications, and network infrastructure.
Monitor Network Traffic and Behavior
Monitoring network traffic and behavior can help identify suspicious activity or anomalies that might indicate an attempted privilege escalation attack. This might include monitoring for unusual traffic patterns, suspicious connections, or other indicators of potentially malicious activity.
Institute a Strong Password Policy
Enforcing strong password policies can help prevent privilege escalation attacks by making it more difficult for attackers to guess or crack passwords. This might include requiring strong passwords, enforcing password expiration, and using two-factor authentication.
Conduct Security Awareness Training
Providing security awareness training to users can help educate them about the risks of privilege escalation attacks and how to prevent them. This might include training on the importance of strong passwords, the dangers of clicking on links or opening attachments from unknown sources, and the need to report suspicious activity.
Preventing Privilege Escalation Attacks with Aqua
To prevent privilege escalation attacks in your environment, it’s essential to regularly scan your container images for potential vulnerabilities with static scanning tools such as Aqua Trivy. It’s a comprehensive and easy-to-use open source security scanner. Unlike other tools, Trivy covers both OS packages and language-specific dependencies and is extremely easy to integrate into organizations’ software development pipelines. You can use Trivy to find vulnerabilities & IaC misconfigurations, perform SBOM discovery, cloud scanning, detect Kubernetes security risks, and more.
- Supply Chain Compliance: 4 Standards You Should Know
- SolarWinds Attack: Play by Play and Lessons Learned
- Supply Chain Security: Mitigating the Supply Chain Threat
- What Is the Secure Software Development Lifecycle (SSDLC)?
- Software Supply Chain Attacks: 6 Examples and 6 Defensive Strategies
- Dependency Confusion Attack
- What Is SLSA and How to Use it for Supply Chain Security
- What Is SSDF (Secure Software Development Framework)?
- What Is Software Composition Analysis (SCA)?
- Security Misconfiguration: Types, Examples & Prevention Tips
- Why Repojacking Is a New Mega Threat & Protecting Your Projects
- CI/CD Security: Threats, Tools, and Best Practices
- SAST Security: Is SAST Still Relevant for Modern Applications?
- GitLab Security
- GitHub Secret Scanning
- How to Analyze the OWASP Dependency-Check?
- SBOM (Software Bill of Materials)
- What Are SBOM Tools?
- 6 Common npm Vulnerabilities and How to Fix Them
- Log4j Vulnerability: Updated Info and Protection for 2023
- Text4Shell CVE (CVE-2022-42889): Impact and Fixes
- What Is Secrets Management? Challenges and Best Practices
- Jenkins Security: How it Works & Best practices
- Yarn vs. NPM: Which Package Manager You Should Choose, and Why?
- Source Code Leaks: How to Avoid Them Before They Happen
- Container Image Signing: A Practical Guide
- 5 Open Source Licenses and Compliance Risks to Know About
- Show more
Aqua Cloud Native Application Protection Platform (CNAPP)
Go cloud native with the experts!