{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/capabilities/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["privilege-escalation","linux","capabilities","root-access"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThis threat involves a Linux privilege escalation technique where attackers exploit misconfigurations related to the CAP_SETUID and CAP_SETGID capabilities. In Linux, these capabilities allow a process to change its User ID (UID) and Group ID (GID) respectively, which is critical for identity management. An adversary can leverage an application or system utility that has been granted these capabilities but is misconfigured, allowing them to execute code with elevated privileges. The detection focuses on identifying processes that are initiated with \u003ccode\u003eCAP_SETUID\u003c/code\u003e or \u003ccode\u003eCAP_SETGID\u003c/code\u003e capabilities, running under a non-root user, and subsequently change their effective UID or GID to 0 (root). This indicates a successful or attempted privilege escalation to gain full control over the compromised system. The technique is a common method for attackers to transition from initial access to a more persistent and controlling posture.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker gains initial access to a Linux system, often as a low-privileged user.\u003c/li\u003e\n\u003cli\u003eThe attacker identifies a misconfigured application or utility with \u003ccode\u003eCAP_SETUID\u003c/code\u003e or \u003ccode\u003eCAP_SETGID\u003c/code\u003e capabilities.\u003c/li\u003e\n\u003cli\u003eThe attacker executes the identified process, which initially runs under the attacker's non-root user context.\u003c/li\u003e\n\u003cli\u003eLeveraging the misconfiguration or vulnerability within the capable process, the attacker manipulates it to change its effective UID or GID to 0 (root).\u003c/li\u003e\n\u003cli\u003eThe system grants the process root privileges based on the successful UID/GID change, despite the initial execution context being non-root.\u003c/li\u003e\n\u003cli\u003eThe attacker now has command execution capabilities as the root user through the context of the elevated process.\u003c/li\u003e\n\u003cli\u003eThe attacker can then perform actions such as installing backdoors, creating new privileged accounts, or disabling security controls.\u003c/li\u003e\n\u003cli\u003eThe final objective, such as data exfiltration or system destruction, is achieved with full administrative control.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eA successful privilege escalation to root via \u003ccode\u003eCAP_SETUID\u003c/code\u003e/\u003ccode\u003eCAP_SETGID\u003c/code\u003e capabilities grants the attacker complete control over the compromised Linux system. This includes the ability to access, modify, or delete any file, install or remove software, create or modify user accounts, disable security measures, and exfiltrate sensitive data without restriction. The impact extends to potential lateral movement to other systems, disruption of critical services, and establishment of persistent unauthorized access, severely compromising the integrity, confidentiality, and availability of affected assets.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReview system configurations to identify and correct any misconfigurations that may inadvertently grant \u003ccode\u003eCAP_SETUID\u003c/code\u003e or \u003ccode\u003eCAP_SETGID\u003c/code\u003e capabilities to unauthorized processes or scripts.\u003c/li\u003e\n\u003cli\u003eRegularly audit \u003ccode\u003eCAP_SETUID\u003c/code\u003e and \u003ccode\u003eCAP_SETGID\u003c/code\u003e binaries on Linux systems to ensure only necessary and properly configured applications possess these capabilities.\u003c/li\u003e\n\u003cli\u003eImplement host-based security monitoring using endpoint detection and response (EDR) solutions like Elastic Defend to log and alert on \u003ccode\u003eprocess_creation\u003c/code\u003e and \u003ccode\u003euid_change\u003c/code\u003e events, especially those involving capability changes.\u003c/li\u003e\n\u003cli\u003eIsolate any affected hosts immediately upon detection of suspicious privilege escalation activity to prevent further compromise or lateral movement.\u003c/li\u003e\n\u003cli\u003eRevoke unnecessary \u003ccode\u003eCAP_SETUID\u003c/code\u003e and \u003ccode\u003eCAP_SETGID\u003c/code\u003e capabilities from processes that do not strictly require them, reducing the attack surface.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-20T12:48:02Z","date_published":"2026-07-20T12:48:02Z","id":"https://feed.craftedsignal.io/briefs/2026-07-privilege-escalation-cap-setuid-setgid/","summary":"This brief details a Linux privilege escalation technique where attackers leverage misconfigurations in applications with CAP_SETUID or CAP_SETGID capabilities to elevate their privileges to root (UID/GID 0), enabling unauthorized system control and further malicious activities.","title":"Linux Privilege Escalation via CAP_SETUID/SETGID Capabilities","url":"https://feed.craftedsignal.io/briefs/2026-07-privilege-escalation-cap-setuid-setgid/"}],"language":"en","title":"CraftedSignal Threat Feed - Capabilities","version":"https://jsonfeed.org/version/1.1"}