Privilege Escalation
CPTS · 40 questions
- A city engagement yields a low-privilege Linux shell on an internal host. What should the tester do first for privilege-escalation situational awareness?
- A county Linux sudoers entry lets a standard user run a text editor as root. How should the tester interpret this class of finding?
- A municipal host has a custom script wrapper marked SUID root that is not a standard system binary. What should the tester conclude?
- A library server runs a root cron job that executes a script writable by unprivileged users. What misconfiguration class is this?
- A transit Linux host has a root-run maintenance job that invokes a command by relative name while PATH can be influenced insecurely. What risk class should the tester document?
- A water utility Linux host mounts an NFS share exported with norootsquash. During privilege-escalation enumeration, how should the tester interpret that export option?
- A city internet-facing Linux box is still running a years-old kernel. How should the tester treat that kernel age during privilege-escalation planning?
- A county Linux host shows file capability bits granting a binary powerful privileges without a traditional SUID bit. What should the tester include in enumeration thinking?
- A municipal low-privilege account is a member of the Docker group on a Linux host. Conceptually, how should the tester frame that membership?
- A library Linux system shows world-writable permissions on /etc/passwd or /etc/shadow-class files. What is the correct severity framing for that finding?
- A transit agency service runs as root and loads its configuration from a directory writable by a low-privilege user. What privilege-escalation theme does that represent?
- A city Linux foothold reveals a cleartext password in a world-readable shell history file. How should the tester treat that discovery during privilege escalation?
- A county Windows foothold is new. Before choosing a privilege-escalation path, what situational awareness should come first?
- A municipal Windows image shows AlwaysInstallElevated-class policy themes enabled. How should the tester classify that finding?
- A library Windows service uses an unquoted binary path containing spaces, and an intermediate folder is writable by the foothold user. What misconfiguration class is this?
- A transit Windows service runs as SYSTEM and its service binary is writable by a standard user. Conceptually, what does that enable?
- A city scheduled task runs elevated and points at a script the low-privilege user can modify. What should the tester conclude?
- A county Windows token shows SeImpersonatePrivilege on an older patch level. How should the tester frame that privilege without diving into exploit steps?
- A municipal elevated application loads DLLs from a path writable by a standard user. What privilege-escalation class should the tester investigate carefully?
- A library IT team uses one shared local administrator password across the entire workstation fleet. After compromising that password on one host, what privilege impact should the tester highlight?
- A water utility Windows host stores autologon credentials in the registry. Why does privilege-escalation enumeration care about that?
- A city workstation fleet has extremely permissive UAC settings. How should the tester include that posture in Windows risk framing?
- A county domain still shows leftover Group Policy Preferences cpassword-class artifacts. What should the Windows privilege-escalation mindset treat them as?
- A municipal high-value server has antivirus disabled and no EDR present. How should the tester report that condition in a privilege-escalation / post-exploitation context?
- A library workstation exposes an unnecessary elevated local service related to printer spooler-class functionality. Without providing exploit steps, what is the sound assessment takeaway?
- A transit engagement includes Linux container breakout in scope. Conceptually, which container traits should the tester enumerate first?
- A city sudo package is old with known public issues, but the rules of engagement ban using public exploits without approval. What is the correct next judgment?
- A county tester has proven a reliable path to local SYSTEM on one Windows host and the next objective involves Active Directory. What distinction must remain clear?
- A municipal low-privilege Linux user can read another user's private SSH keys due to weak home-directory permissions. What is the primary risk?
- A library Windows host runs an outdated third-party kernel driver. Why should privilege-escalation enumeration include that class of software?
- A transit agency has a Samba share that allows guest write next to a Linux cron job that ingests that share as a privileged user. Which class of privilege-escalation risk does this multi-service layout best illustrate?
- A city asks the tester to spend remaining time only on a CTF-style kernel exploit that depends on rare race conditions, while common local misconfigs remain unreviewed. What should the tester prefer for CPTS-style value?
- A county Windows host shows PowerShell history and transcription logs that appear to capture prior admin commands. What is the best privilege-escalation enumeration takeaway?
- A municipal Linux backup script runs as root and embeds database credentials in clear text. How should the tester frame this during privilege-escalation review?
- A library Windows service account can RDP interactively and is also a local administrator on additional hosts. Which risk class should the finding emphasize?
- A water utility marks a SCADA Windows host as forbidden for any privilege-escalation testing. What is the correct professional response?
- A city Linux host grants broad capabilities to a Python interpreter used by operators. How should the tester treat this finding class?
- A county engagement confirms local privilege escalation. Which evidence approach best matches least-impact professional proof?
- A municipal Windows estate shows long WSUS or update offline periods leaving hosts unpatched. How does that relate to privilege-escalation likelihood?
- A transit engagement finds both Linux and Windows local privilege escalations. How should reporting best help different system owners?