Start with Identity
← Glossary
Threat

Privilege Escalation

Gaining higher access than originally granted, by exploiting misconfigurations, vulnerabilities, or over-permissioned identities. Tightly linked to privileged access risk.

Most real escalations are not exploits, they are configuration: a group that grants more than anyone realized, a role that can modify its own policy, a certificate template with dangerous permissions, or a service account with domain rights. That is why attack-path analysis across the identity graph finds more than vulnerability scanning does, and why the fix is usually a permission change rather than a patch.

See also: lateral movement, least privilege, what is PAM, identity CVE catalog

Last reviewed By SWI Community TeamSuggest a correctionHow we research