Overview
Vertical escalation jumps a normal user to admin, often through an unchecked function-level access control gap or a kernel/local exploit.\nHorizontal escalation stays at the same level but crosses into another tenant's data, which is just as damaging in multi-tenant apps.\nEither way the attacker gains capabilities the design never intended to expose.
Indicators of Compromise
Signals that suggest this is present on a system.
- Ordinary users reaching admin endpoints
- Role read from a client-controlled header or cookie
- Kernel exploit tooling present on the host
Controls that stop it
-
Apply Least Privilege Everywhere
Give accounts, processes, tokens and service principals the minimum permissions needed, for the minimum time. Review admin rights and service accounts on a schedule, remove standing privilege, and prefer short-lived credentials over long-lived keys. Deny by default so a missing check fails closed rather than open.