Standardlikelihood: Lowseverity: Very HighDraft
CAPEC-480Escaping Virtualization
Abstraction
Standard
Status
Draft
Likelihood
Low
Severity
Very High
Description
An adversary gains access to an application, service, or device with the privileges of an authorized or privileged user by escaping the confines of a virtualized environment. The adversary is then able to access resources or execute unauthorized code within the host environment, generally with the privileges of the user running the virtualized process. Successfully executing an attack of this type is often the first step in executing more complex attacks.
Related weaknesses· 1
MITRE ATT&CK crosswalk· 1
Related attack patterns· 1
Exploits1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Protection Mechanism Failurecwe-693 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Technique | Escape to Hostt1611 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.