Kai Ole Hartwig

name of the term: Local Privilege Escalation (LPE)
descriptions of the term:

Definition

Definition. A class of vulnerabilities in which an attacker who already has local access to a system with limited privileges can escalate to higher privileges (e.g. root). LPE flaws often sit in the kernel, in privileged helper processes (sudo, polkit) or in misconfigured SUID binaries.

Why it matters. LPE is often played down as “only local”. In reality it is the link between a compromised container, a stolen service account or a phishing session and a full takeover.

Related. Kernel LPE, Container Escape, CVE, Kernel Hardening

Type of term: acronym
Language of the term (2 char ISO code): en
Back