CAPEC Definitions

    CAPEC Definitions / CAPEC-669

    CAPEC-669: Alteration of a Software Update

    An adversary with access to an organization’s software update infrastructure inserts malware into the content of an outgoing update to fielded systems where a wide range of malicious effects are possible. With the same level of access, the adversary can alter a software update to perform specific malicious acts including granting the adversary control over the software’s normal functionality.

    Severity:High
    Possibility:Medium

    Extended Description

    No Extended Description.

    Mitigations

    Have a Software Assurance Plan that includes maintaining strict configuration management control of source code, object code and software development, build and distribution tools; manual code reviews and static code analysis for developmental software; and tracking of all storage and movement of code.

    Require elevated privileges for distribution of software and software updates.

    Relationships with other CAPECs

    CAPEC-184: Software Integrity Attack

    CAPEC-673: Developer Signing Maliciously Altered Software

    Prerequisites

    An adversary would need to have penetrated an organization’s software update infrastructure including gaining access to components supporting the configuration management of software versions and updates related to the software maintenance of customer systems.

    Related Weaknesses

    No related Weaknesses found.

    CAPEC-669: Alteration of a Software Update | CVE-DB