CAPEC-642 Metadata
Likelihood of Attack
Low
Typical Severity
High
Overview
Summary
Adversaries know that certain binaries will be regularly executed as part of normal processing. If these binaries are not protected with the appropriate file system permissions, it could be possible to replace them with malware. This malware might be executed at higher system permission levels. A variation of this pattern is to discover self-extracting installation packages that unpack binaries to directories with weak file permissions which it does not clean up appropriately. These binaries can be replaced by malware, which can then be executed.
Prerequisites
The attacker must be able to place the malicious binary on the target machine.
Potential Solutions / Mitigations
Insure that binaries commonly used by the system have the correct file permissions. Set operating system policies that restrict privilege elevation of non-Administrators. Use auditing tools to observe changes to system services.
Related Weaknesses (CWE)
CWE ID | Description |
---|---|
CWE-732 | Incorrect Permission Assignment for Critical Resource |
Related CAPECs
CAPEC ID | Description |
---|---|
CAPEC-17 | An attack of this type exploits a system's configuration that allows an adversary to either directly access an executable file, for example through shell access; or in a possible worst case allows an adversary to upload a file and then execute it. Web servers, ftp servers, and message oriented middleware systems which have many integration points are particularly vulnerable, because both the programmers and the administrators must be in synch regarding the interfaces and the correct privileges for each interface. |
Taxonomy Mappings
Taxonomy: ATTACK
Entry ID | Entry Name |
---|---|
1505.005 | Server Software Component: Terminal Services DLL |
1554 | Compromise Client Software Binary |
1574.005 | Hijack Execution Flow:Executable Installer File Permissions Weakness |
Taxonomy: OWASP Attacks
Entry ID | Entry Name |
---|---|
Link | Binary planting |
Stay Ahead of Attack Patterns
Understanding CAPEC patterns helps security professionals anticipate and thwart potential attacks. Leverage these insights to enhance threat modeling, strengthen your software development lifecycle, and train your security teams effectively.