权限提升(Privilege Escalation)与授权绕过(Authorization Bypass)的区别
Great question—this is a super common point of confusion in security, so let’s break down the core differences with concrete, relatable examples to clarify things.
权限提升(Privilege Escalation)
At its core, privilege escalation is when you gain access to a higher-privilege identity that you weren’t originally assigned, then perform actions using that elevated identity. You’re essentially "promoting" your own permission level to something higher, and all subsequent actions are executed under that new, more powerful role.
Examples:
- Suppose you’re a regular employee at a company. You exploit a vulnerability to steal the admin’s password, log in as the admin, and delete sensitive system logs that only admins can access. This is privilege escalation: you first acquired the admin’s identity, then used that identity to perform a restricted action.
- For local system scenarios: You’re a standard Windows user, and you use a kernel vulnerability to upgrade your permissions to
SYSTEMlevel. Now you can modify system registry keys or install software that regular users can’t. Here, your actual permission level is elevated—you’re no longer acting as a regular user.
授权绕过(Authorization Bypass)
Authorization bypass is about skipping the system’s authorization checks without changing your identity. You remain a low-privilege user, but you find a way to get the system to let you perform actions it should block for your role.
Examples:
- You’re a regular user on a web app, and the admin-only endpoint for deleting users is
/admin/delete-user?id=123. You paste this URL into your browser, and the system doesn’t verify that you’re an admin—so you delete a user anyway. This is authorization bypass: your identity is still "regular user," but you bypassed the check that should restrict this endpoint to admins. - Another example: An e-commerce site lets you view your own orders at
/orders/{orderId}. You change theorderIdto someone else’s, and the system doesn’t check if the order belongs to you. You can now view another user’s order details. Again, your identity hasn’t changed—you just bypassed the resource-specific authorization check.
Key Differences at a Glance
- Identity Change: Privilege escalation modifies your actual permission level/identity; authorization bypass leaves your identity unchanged.
- System Perspective: After escalation, the system sees you as a high-privilege user (so your actions are "legitimate" from its view—only the way you gained the privilege is malicious). With bypass, the system should have blocked your action, but you slipped past the check.
- Scope: Privilege escalation often gives you broad access to all actions the elevated role can perform. Authorization bypass is usually targeted at specific actions or resources—you might not gain full admin access, just the ability to do one restricted thing.
内容的提问来源于stack exchange,提问作者Tarek Mohamed

