With most articles like this the assumption is that the user has been compromised. While it’s a real thing it’s not that real. MANY systems do not have traditional users in the sense and/or all users are actually admins… so this is generally crap.
Linux Privilege Escalation using Capabilities – https://www.hackingarticles.in/linux-privilege-escalation-using-capabilities/