Standardlikelihood: Lowseverity: Very HighDraft
CAPEC-30Hijacking a Privileged Thread of Execution
Abstraction
Standard
Status
Draft
Likelihood
Low
Severity
Very High
Description
An adversary hijacks a privileged thread of execution by injecting malicious code into a running process. By using a privleged thread to do their bidding, adversaries can evade process-based detection that would stop an attack that creates a new process. This can lead to an adversary gaining access to the process's memory and can also enable elevated privileges. The most common way to perform this attack is by suspending an existing thread and manipulating its memory.
Related weaknesses· 1
MITRE ATT&CK crosswalk· 1
Related attack patterns· 1
Exploits1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Privilege Context Switching Errorcwe-270 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Thread Execution Hijackingt1055.003 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.