Courseiva

Privilege Escalation by Exploiting Vulnerable SUID Binaries on Linux

During a penetration test, you gain initial access to a Linux server as a low-privileged user. The target runs a vulnerable SUID binary owned by root. Which of the following is the MOST effective method to escalate privileges?

Quick Answer

The answer is exploiting the SUID binary to execute commands as root. This is correct because a Set User ID (SUID) binary owned by root runs with the file owner’s elevated privileges, regardless of who executes it. When such a binary is vulnerable—for example, through command injection, path hijacking, or improper argument handling—a low-privileged user can leverage it to spawn a root shell or run arbitrary commands with root-level access. On the Certified Ethical Hacker CEH exam, this technique tests your understanding of Linux file permissions and post-exploitation enumeration, often appearing in scenario-based questions where you must identify the fastest path to root after initial access. A common trap is confusing SUID with SGID or overlooking binaries like `find`, `vim`, or `nmap` that have known privilege escalation vectors. Memory tip: “SUID + root owner + vulnerable = instant root shell.”

⚠ Common exam trap

Candidates often confuse enumeration techniques (SMTP VRFY, enum4linux) or standard sudo checks with direct privilege escalation methods, overlooking the immediate root-level access provided by exploiting a vulnerable SUID binary.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Exploit the SUID binary to execute commands as root

The SUID binary owned by root runs with root privileges regardless of the user executing it. Exploiting a vulnerable SUID binary (e.g., via command injection, buffer overflow, or misconfigured capabilities) allows the low-privileged user to execute arbitrary commands as root, directly escalating privileges. This is the most effective method because it leverages a known privilege escalation vector specific to Linux SUID binaries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Perform an SMTP VRFY attack to enumerate users

    Why it's wrong here

    SMTP VRFY enumerates mail users over port 25 and never executes the root-owned SUID binary, so no privilege boundary is crossed. It is tempting as a reconnaissance step for harvesting usernames before password attacks, which is its actual purpose in a mail-service engagement.

  • ✓

    Exploit the SUID binary to execute commands as root

    Why this is correct

    A SUID binary owned by root executes with root's effective UID regardless of the invoking user. Exploiting it to run commands therefore yields a root shell directly, which is more reliable than kernel exploits or misconfigured cron jobs.

  • ✗

    Use enum4linux to enumerate SMB shares

    Why it's wrong here

    enum4linux queries SMB and NetBIOS services on Windows hosts; it cannot execute a local root-owned SUID binary on Linux, so no escalation occurs. It is tempting during SMB-focused enumeration, and would be correct when mapping shares, users and policies on a Windows target.

  • ✗

    Run 'sudo -l' to list sudo privileges

    Why it's wrong here

    'sudo -l' only lists permitted sudo commands; it does not exploit the vulnerable SUID binary, so no root shell is obtained. It is tempting because it is a standard first enumeration step, and it would be correct if the misconfiguration were an over-permissive sudoers entry rather than a SUID binary.

About these practice questions

This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CEH

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. During a penetration test, you gain access to a Linux server as a low-privileged user. Which of the following is an effective technique to escalate privileges by exploiting misconfigured file permissions?

medium
  • A.Pass-the-hash
  • B.Token impersonation
  • ✓ C.SUID/GUID abuse
  • D.Kerberoasting

Why C: SUID (Set User ID) and GUID (Group ID) bits allow a binary to execute with the privileges of the file owner (often root) rather than the calling user. If a low-privileged user can run a binary with the SUID bit set that performs unsafe operations (e.g., spawning a shell, reading arbitrary files, or executing commands), they can leverage it to gain root-level access. This is a classic privilege escalation vector on Linux systems when file permissions are misconfigured.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.