privilege-escalation
Safeguard articles tagged "privilege-escalation" — guides, analysis, and best practices for software supply chain and application security.
50 articles
Your Access Review Checks One Node in a Graph
A user's permission listing shows no administrative access. By every direct check, they are ordinary. They can still become an administrator through a permission that looks unrelated, was granted for an unrelated reason, and lets them modify something that leads there.
A Sudo Bug Let Local Users Reach Root Without Ever Appearing in Sudoers
CVE-2025-32463 let any local user leverage sudo's --chroot option to run commands as root, bypassing the sudoers access-control model entirely.
The Windows CLFS Driver Produced a Second Confirmed-Exploited CVE, Two Years Apart
CVE-2023-36424 and CVE-2021-43226 both hit the same Windows Common Log File System Driver, one carrying a confirmed ransomware association, plus a separate Desktop Window Manager information leak.
A Read-Only API Key Was Enough to Overwrite Files on Cisco SD-WAN Manager
CVE-2026-20122, an additional Cisco Catalyst SD-WAN Manager finding beyond this series' earlier coverage, shows how a low-privilege API credential can still enable a file-write escalation.
LiteSpeed's cPanel Plugin: A Symlink Escape and a Root Privilege Escalation, Weeks Apart
Two LiteSpeed cPanel plugin vulnerabilities confirmed exploited in May 2026 form a plausible escalation chain from any tenant account to root on shared hosting infrastructure.
Android Framework and Qualcomm Chipsets: Four CVEs Across the Mobile Stack
Three Android Framework privilege-escalation bugs and a Qualcomm chipset memory corruption flaw, confirmed exploited across the software and silicon layers of the Android ecosystem.
Three Linux Kernel Privilege Escalation Bugs, Three Unrelated Subsystems, One Shared Trust Boundary
A netfilter heap overflow, an ELF-loading integer overflow, and a crypto API resource-transfer bug all reached CISA's KEV within a year — each a fresh failure of the same local privilege boundary.
Nine Windows Privilege Escalation Bugs Confirmed Exploited — Why the Quiet Ones Matter Most
Nine local privilege-escalation and access-control vulnerabilities in Windows were confirmed exploited over the past year. None individually dramatic, together they define how far an intrusion spreads.
Microsoft Defender Had Three of Its Own Vulnerabilities Confirmed Exploited
Security software is software first: two local privilege-escalation bugs and a denial-of-service flaw in Microsoft Defender itself were confirmed exploited in the wild.
Four Microsoft CVEs Describe a Complete Access-to-Domain-Control Chain
One unauthenticated RCE and three local privilege-escalation bugs across Windows and Active Directory Federation Services, confirmed exploited between July and September 2026.
CVE-2026-68820: A 7.0 That Ends With a Kernel Rootkit and Your EDR Switched Off
Lazarus used this afd.sys use-after-free to reach SYSTEM from a local foothold, then loaded a FudModule kernel rootkit. Escalation is never the objective — it is the step before it.
Docker Engine remap-root UID mapping vulnerability (CVE-2021-21284)
CVE-2021-21284 let remapped-root containers escalate to real host root, defeating Docker's userns-remap isolation. Here's the full breakdown and fix.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.