Exploitation for Privilege Escalation

T1068

Technique.View on attack.mitre.org

About this technique

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

When initially gaining access to a system, an adversary may be operating within a lower privileged process which will prevent them from accessing certain resources on the system. Vulnerabilities may exist, usually in operating system components and software commonly running at higher permissions, that can be exploited to gain higher levels of access on the system. This could enable someone to move from unprivileged or user level permissions to SYSTEM or root permissions depending on the component that is vulnerable. This could also enable an adversary to move from a virtualized environment, such as within a virtual machine or container, onto the underlying host. This may be a necessary step for an adversary compromising an endpoint system that has been properly configured and limits other privilege escalation methods.

Adversaries may bring a signed vulnerable driver onto a compromised machine so that they can exploit the vulnerability to execute code in kernel mode. This process is sometimes referred to as Bring Your Own Vulnerable Driver (BYOVD). Adversaries may include the vulnerable driver with files delivered during Initial Access or download it to a compromised system via Ingress Tool Transfer or Lateral Tool Transfer.

Detection rules72

Rules on DetectionCode tagged with T1068.

Sigma19

RuleLevelLog source
Audit CVE Eventcriticalwindows / NULL
HackTool - SysmonEOP Executioncriticalwindows / process_creation
Possible Coin Miner CPU Priority Paramcriticallinux / NULL
Sudo Privilege Escalation CVE-2019-14287 - Builtincriticallinux / NULL
Buffer Overflow Attemptshighlinux / NULL
HKTL - SharpSuccessor Privilege Escalation Tool Executionhighwindows / process_creation
Malicious Driver Loadhighwindows / driver_load
Nimbuspwn Exploitationhighlinux / NULL
OMIGOD HTTP No Authentication RCEhighzeek / NULL
OMIGOD SCX RunAsProvider ExecuteScripthighlinux / process_creation
OMIGOD SCX RunAsProvider ExecuteShellCommandhighlinux / process_creation
Process Explorer Driver Creation By Non-Sysinternals Binaryhighwindows / file_event
Sudo Privilege Escalation CVE-2019-14287highlinux / process_creation
Suspicious Spool Service Child Processhighwindows / process_creation
Vulnerable Driver Loadhighwindows / driver_load

Splunk53

RuleTypeRiskData source
Child Processes of Spoolsv exeTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Cisco Isovalent - Kprobe SpikeHuntingNULLCisco Isovalent Process Kprobe
Detect Baron Samedit CVE-2021-3156TTPNULL
Detect Baron Samedit CVE-2021-3156 SegfaultTTPNULL
Detect Baron Samedit CVE-2021-3156 via OSQueryTTPNULL
First Time Seen Child Process of ZoomAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Linux Apparmor Bypass Via AaexecTTPNULLSysmon for Linux EventID 1
Linux Auditd Copy Fail Privilege EscalationTTPNULLLinux Auditd Syscall
Linux Auditd Possible Setuid Execve PrivescAnomalyNULLLinux Auditd Execve
Linux Binary Launched Process with Null ArgvTTPNULLLinux Messages Syslog
Linux Dirty Frag Kernel Privilege EscalationTTPNULLLinux Auditd Syscall
Linux Ghostscript ExploitationTTPNULLSysmon for Linux EventID 1
Linux Malformed Auth EntryAnomalyNULLLinux Secure
Linux Pedit Offset Out Of BoundsTTPNULLLinux Messages Syslog
Linux PF_ALG Registration Outside of Boot WindowTTPNULLLinux Messages Syslog

Groups22

Software19

Campaigns2

Procedure examples43

Groups22

Used byProcedure example
GroupAPT28

APT28 has exploited CVE-2014-4076, CVE-2015-2387, CVE-2015-1701, CVE-2017-0263, and CVE-2022-38028 to escalate privileges.

GroupAPT29

APT29 has exploited CVE-2021-36934 to escalate privileges on a compromised host.

GroupAPT32

APT32 has used CVE-2016-7255 to escalate privileges.

GroupAPT33

APT33 has used a publicly available exploit for CVE-2017-0213 to escalate privileges on a local system.

GroupBITTER

BITTER has exploited CVE-2021-1732 for privilege escalation.

GroupBlackByte

BlackByte has exploited CVE-2024-37085 in VMWare ESXi software for authentication bypass and subsequent privilege escalation.

GroupCobalt Group

Cobalt Group has used exploits to increase their levels of rights and privileges.

GroupFIN6

FIN6 has used tools to exploit Windows vulnerabilities in order to escalate privileges. The tools targeted CVE-2013-3660, CVE-2011-2005, and CVE-2010-4398, all of which could allow local users to access kernel-level privileges.

View all 22 groups examples

Software19

Used byProcedure example
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware exploits a vulnerability in the RTCore64.sys driver (CVE-2019-16098) to enable privilege escalation and defense evasion when run as a service.

MalwareCarberp

Carberp has exploited multiple Windows vulnerabilities (CVE-2010-2743, CVE-2010-3338, CVE-2010-4398, CVE-2008-1084) and a .NET Runtime Optimization vulnerability for privilege escalation.

MalwareCobalt Strike

Cobalt Strike can exploit vulnerabilities such as MS14-058.

MalwareCosmicDuke

CosmicDuke attempts to exploit privilege escalation vulnerabilities CVE-2010-0232 or CVE-2010-4398.

MalwareEmbargo

Embargo has leveraged MS4Killer to deliver a vulnerable driver to the victim device, sometimes referred to as Bring Your Own Vulnerable Driver (BYOVD). Embargo has utilized the vulnerable driver probmon.sys version 3.0.0.4 which had a revoked certificated from “ITM System Co.,LTD.”

ToolEmpire

Empire can exploit vulnerabilities such as MS16-032 and MS16-135.

MalwareHildegard

Hildegard has used the BOtB tool which exploits CVE-2019-5736.

MalwareInvisiMole

InvisiMole has exploited CVE-2007-5633 vulnerability in the speedfan.sys driver to obtain kernel mode privileges.

View all 19 software examples

Campaigns2

Used byProcedure example
CampaignLeviathan Australian Intrusions

Leviathan exploited software vulnerabilities in victim environments to escalate privileges during Leviathan Australian Intrusions.

CampaignShadowRay

During ShadowRay, threat actors downloaded a privilege escalation payload to gain root access.

References2

  1. ESET InvisiMole June 2020 Open source
    Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.
  2. Unit42 AcidBox June 2020 Open source
    Reichel, D. and Idrizovic, E. (2020, June 17). AcidBox: Rare Malware Repurposing Turla Group Exploit Targeted Russian Organizations. Retrieved March 16, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.