A penetration tester gains access to a Linux server and attempts to escalate privileges. They run `sudo -l` and see that the user can run `/usr/bin/vim` as root without a password. Which privilege escalation technique should the tester use?
This is the correct approach because if vim is launched with sudo privileges, even if sudo is configured to require a password, the vim process itself will be running as root. Within vim, the :!bash command allows the user to execute an arbitrary shell command. Since vim is already running as root, the spawned bash shell will inherit these root privileges, effectively granting a root shell without needing to know the root password directly.
Why this answer
The `sudo -l` output shows that the user can run `/usr/bin/vim` as root without a password. Vim has a built-in shell escape feature: from within vim, typing `:!bash` (or `:!sh`) executes a shell with the privileges of the user running vim. Since vim is run via sudo as root, the spawned shell will be a root shell, directly escalating privileges without needing additional exploits.
Exam trap
CEH exams often test the distinction between sudo-based privilege escalation and SUID-based escalation; the trap here is that candidates may incorrectly focus on the SUID bit (Option D) when the actual vector is the sudo rule allowing arbitrary command execution via vim's shell escape.
How to eliminate wrong answers
Option A is wrong because token impersonation using SeImpersonatePrivilege is a Windows-specific privilege escalation technique (e.g., JuicyPotato), not applicable to Linux. Option C is wrong because exploiting a kernel vulnerability (CVE-2023-xxxx) is unnecessary when a simple sudo misconfiguration already grants root access; it is overkill and risks system instability. Option D is wrong because the SUID bit on vim is not relevant here; the user already has sudo permission to run vim as root, so the escalation vector is the sudo rule, not the SUID bit.