Standardseverity: MediumDraft
CAPEC-234Hijacking a privileged process
Abstraction
Standard
Status
Draft
Severity
Medium
Description
An adversary gains control of a process that is assigned elevated privileges in order to execute arbitrary code with those privileges. Some processes are assigned elevated privileges on an operating system, usually through association with a particular user, group, or role. If an attacker can hijack this process, they will be able to assume its level of privilege in order to execute their own code.
Related weaknesses· 2
Related attack patterns· 4
Exploits2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Incorrect Use of Privileged APIscwe-648 | 100% | live |
| Weakness | Incorrect Permission Assignment for Critical Resourcecwe-732 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.