A city internet-facing Linux box is still running a years-old kernel. How should the tester treat that kernel age during privilege-escalation planning?
Select an answer to reveal the explanation.
Short Explanation
An ancient kernel is like a rusty lock on the front door—it screams "check this," but you still do not kick every door with a battering ram. Age raises the chance of known local privilege classes, yet RoE and careful validation still rule. Enumerate, prioritize, then only use approved techniques.
Full Explanation
Older kernels frequently correlate with published local privilege-escalation classes, so age is a useful triage signal during Linux enumeration. It is not a free pass to spray public exploits, nor proof of immunity. Professional CPTS-style judgment prioritizes the lead, confirms relevance to the build, and respects rules of engagement before any elevated technique. Local situational awareness remains required even when the kernel looks outdated.