Detailedseverity: MediumStable
CAPEC-471Search Order Hijacking
Abstraction
Detailed
Status
Stable
Severity
Medium
Description
An adversary exploits a weakness in an application's specification of external libraries to exploit the functionality of the loader where the process loading the library searches first in the same directory in which the process binary resides and then in other directories. Exploitation of this preferential search order can allow an attacker to make the loading process load the adversary's rogue library rather than the legitimate library. This attack can be leveraged with many different libraries and with many different loading processes. No forensic trails are left in the system's registry or file system that an incorrect library had been loaded.
Related weaknesses· 1
MITRE ATT&CK crosswalk· 3
Related attack patterns· 1
Exploits1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Uncontrolled Search Path Elementcwe-427 | 100% | live |
Related to3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | DLL Search Order Hijackingt1574.001 | 100% | live |
| SubTechnique | Dylib Hijackingt1574.004 | 100% | live |
| SubTechnique | Path Interception by Search Order Hijackingt1574.008 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.