Detailedlikelihood: Highseverity: Very HighStable

CAPEC-13Subverting Environment Variable Values

Abstraction
Detailed
Status
Stable
Likelihood
High
Severity
Very High

Description

The adversary directly or indirectly modifies environment variables used by or controlling the target software. The adversary's goal is to cause the target software to deviate from its expected operation in a manner that benefits the adversary. Metadata: detailed CAPEC pattern, status stable, likelihood high, severity very high. Underlying weaknesses: CWE-353, CWE-285, CWE-302, CWE-74, CWE-15 (and 3 more). Mapped ATT&CK techniques: [object Object], [object Object], [object Object]. Related CAPEC patterns: [object Object], [object Object], [object Object].

Related weaknesses· 8

CWE-353CWE-285CWE-302CWE-74CWE-15CWE-73CWE-20CWE-200

MITRE ATT&CK crosswalk· 3

T1562.003: Impair Defenses:Impair Command History LoggingT1574.006: Hijack Execution Flow:Dynamic Linker HijackingT1574.007: Hijack Execution Flow:Path Interception by PATH Environment Variable

Related attack patterns· 3

CAPEC-77 (ChildOf)CAPEC-14 (CanPrecede)CAPEC-10 (PeerOf)

Exploits8

TypeTargetConfidenceTier
WeaknessMissing Support for Integrity Checkcwe-353100%live
WeaknessExposure of Sensitive Information to an Unauthorized Actorcwe-200100%live
WeaknessExternal Control of File Name or Pathcwe-73100%live
WeaknessExternal Control of System or Configuration Settingcwe-15100%live
WeaknessImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')cwe-74100%live
WeaknessAuthentication Bypass by Assumed-Immutable Datacwe-302100%live
WeaknessImproper Authorizationcwe-285100%live
WeaknessImproper Input Validationcwe-20100%live

Related to3

TypeTargetConfidenceTier
SubTechniquePath Interception by PATH Environment Variablet1574.007100%live
SubTechniqueImpair Command History Loggingt1562.003100%live
SubTechniqueDynamic Linker Hijackingt1574.006100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
DEPRECATED: Environment Variable Manipulation
CAPEC
Buffer Overflow via Environment Variables
CAPEC
Configuration/Environment Manipulation
CAPEC
Manipulating User-Controlled Variables
CAPEC
Software Integrity Attack
CAPEC
Force the System to Reset Values
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.