CAPEC Definitions

    CAPEC Definitions / CAPEC-17

    CAPEC-17: Using Malicious Files

    An attack of this type exploits a system's configuration that allows an adversary to either directly access an executable file, for example through shell access; or in a possible worst case allows an adversary to upload a file and then execute it. Web servers, ftp servers, and message oriented middleware systems which have many integration points are particularly vulnerable, because both the programmers and the administrators must be in synch regarding the interfaces and the correct privileges for each interface.

    Severity:Very High
    Possibility:High

    Extended Description

    No Extended Description.

    Mitigations

    Design: Enforce principle of least privilege

    Design: Run server interfaces with a non-root account and/or utilize chroot jails or other configuration techniques to constrain privileges even if attacker gains some limited access to commands.

    Implementation: Perform testing such as pen-testing and vulnerability scanning to identify directories, programs, and interfaces that grant direct access to executables.

    Relationships with other CAPECs

    CAPEC-122: Privilege Abuse

    CAPEC-233: Privilege Escalation

    Prerequisites

    System's configuration must allow an attacker to directly access executable files or upload files to execute. This means that any access control system that is supposed to mediate communications between the subject and the object is set incorrectly or assumes a benign environment.

    Related Weaknesses

    CWE-732: Incorrect Permission Assignment for Critical Resource

    CWE-285: Improper Authorization

    CWE-272: Least Privilege Violation

    CWE-59: Improper Link Resolution Before File Access ('Link Following')

    CWE-282: Improper Ownership Management

    CWE-270: Privilege Context Switching Error

    CWE-693: Protection Mechanism Failure