T1068 Exploitation for Privilege Escalation — ATT&CK Technique
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions. When initially gaining access to a system, an adversary may be operating within a lower privileged process which will prevent them from accessing certain resources on the system. Vulnerabilities may exist, usually in operating system components and software commonly running at higher permissions, that can be exploited to gain higher levels of access on the system. This could enable someone to move from unprivileged or user level permissions to SYSTEM or root permissions depending on the component that is vulnerable. This could also enable an adversary to move from a virtualized environment, such as within a virtual machine or container, onto the underlying host. This may be a necessary step for an adversary compromising an endpoint system that has been properly configured and limits other privilege escalation methods. Adversaries may bring a signed vulnerable driver onto a compromised machine so that they can exploit the vulnerability to execute code in kernel mode. This process is sometimes referred to as Bring Your Own Vulnerable Driver (BYOVD). Adversaries may include the vulnerable driver with files delivered during Initial Access or download it to a compromised system via Ingress Tool Transfer or Lateral Tool Transfer.
Detection coverage (50)
- Sudo Privilege Escalation CVE-2019-14287 - Builtin critical
- Sudo Privilege Escalation CVE-2019-14287 high
- Exploiting CVE-2019-1388 critical
- Exploiting SetupComplete.cmd CVE-2019-1378 high
- OMIGOD SCX RunAsProvider ExecuteScript high
- OMIGOD HTTP No Authentication RCE - CVE-2021-38647 high
- InstallerFileTakeOver LPE CVE-2021-41379 File Create Event critical
- Potential CVE-2021-41379 Exploitation Attempt critical
- Potential SystemNightmare Exploitation Attempt critical
- Potential Nimbuspwn Exploit CVE-2022-29799 and CVE-2022-27800 high
- Suspicious Sysmon as Execution Parent high
- Potential CVE-2024-35250 Exploitation Activity medium
- Non-Standard Nsswitch.Conf Creation - Potential CVE-2025-32463 Exploitation high
- Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309) high
- Potential Zerologon (CVE-2020-1472) Exploitation high
- Possible Coin Miner CPU Priority Param critical
- Buffer Overflow Attempts high
- Linux Sudo Chroot Execution low
- OMIGOD SCX RunAsProvider ExecuteShellCommand high
- Audit CVE Event critical
- Vulnerable Driver Load high
- Malicious Driver Load By Name medium
- Malicious Driver Load high
- Vulnerable Driver Load By Name low
- Process Explorer Driver Creation By Non-Sysinternals Binary high
- Process Monitor Driver Creation By Non-Sysinternals Binary medium
- HackTool - SysmonEOP Execution critical
- HKTL - SharpSuccessor Privilege Escalation Tool Execution high
- Suspicious Spool Service Child Process high
- Linux AF_ALG Socket Creation - Kernel Crypto API Exploit Indicator high
- Authencesn Crypto Module Load via Modprobe - Copy-Fail Indicator high
- Linux Binary Launched Process with Null Argv
- Child Processes of Spoolsv exe
- Cisco Isovalent - Kprobe Spike
- First Time Seen Child Process of Zoom
- Detect Baron Samedit CVE-2021-3156
- Detect Baron Samedit CVE-2021-3156 Segfault
- Detect Baron Samedit CVE-2021-3156 via OSQuery
- Linux Auditd Copy Fail Privilege Escalation
- Linux Malformed Auth Entry
- Linux PF_ALG Registration Outside of Boot Window
- Linux pkexec Privilege Escalation
- Linux Suspicious Namespace Creation
- Spoolsv Suspicious Process Access
- Windows Admin Password Changed by Non-Admin
- Windows Cloud Files Filter Log Created by Non-System Process
- Windows Driver Load Non-Standard Path
- Windows Driver Inventory
- Windows Drivers Loaded by Signature
- Linux Possible GSM Privilege Escalation
Malware using this technique
- Embargo
- Remsec
- PoshC2
- ZeroCleare
- Cobalt Strike
- Empire
- Pandora
- Carberp
- CosmicDuke
- BlackByte 2.0 Ransomware
- InvisiMole
- JHUHUGIT
- Stuxnet
- Siloscape
- XCSSET
- Zox
- ProLock
- Wingbird
- Hildegard