logo

Unlocking Power Safely: Privilege Escalation via Linux Process Capabilities

ID: 1126b88a-2c8d-5dc1-b915-ac99c6e48d43

STIX ID: report--1126b88a-2c8d-5dc1-b915-ac99c6e48d43

Feed Name: Elastic Security Labs

Date Published: 2024-03-27

Date Updated: 2026-04-27

...
...

This report explains how Linux process capabilities can be misconfigured or abused to achieve privilege escalation, detailing risks such as unnecessary capability assignment, capability inheritance, vulnerable setuid/setgid binaries, kernel flaws, bounding set issues, and misuse of file attributes. It offers mitigation guidance rooted in least privilege, auditing, secure configuration, proper bounding set usage, patching, hardening (SELinux/AppArmor), integrity checks, and monitoring. The report also highlights Elastic Security 8.11+ prebuilt detection rules and telemetry (CapPrm and CapEff) to identify discovery and privilege-escalation behaviors involving capabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.