Privilege escalation
Gaining rights beyond those currently held: a managed practice when a user runs approved privileged commands under policy with logging, and an attack when the elevation is unauthorised.
Privilege escalation has two meanings, and the ISC2 exam outline’s objective 5.5 uses the managed one: “Privilege escalation (e.g., use of sudo, auditing its use)”. In that sense a user who normally works without administrative rights runs a specific privileged command under a policy that names who may run what, and each use is logged and reviewed. sudo on Unix-like systems is the outline’s example. NIST SP 800-53 Rev. 5 supports the pattern with AC-6(9), logging the use of privileged functions, and AC-6(10), preventing non-privileged users from executing them.
As an attack, privilege escalation means gaining rights the attacker is not entitled to. Vertical escalation moves up to higher rights, such as a standard user becoming an administrator. Horizontal escalation reaches another user’s rights at the same level, such as reading a peer’s records. The managed form’s value lies in its policy and its audit trail: a rule that allows any command loses the policy half and keeps only the log, and a shared root password loses both. Least privilege and privileged access management narrow the room for both kinds.
Exam relevance: questions in this area tend to use both senses. Candidates are expected to tell vertical from horizontal escalation, and to see that controlled elevation works only with a narrow policy and audited use.