Detailedlikelihood: Lowseverity: HighStable
CAPEC-558Replace Trusted Executable
Abstraction
Detailed
Status
Stable
Likelihood
Low
Severity
High
Description
An adversary exploits weaknesses in privilege management or access control to replace a trusted executable with a malicious version and enable the execution of malware when that trusted executable is called.
Metadata: detailed CAPEC pattern, status stable, likelihood low, severity high. Underlying weakness: CWE-284. Mapped ATT&CK techniques: [object Object], [object Object]. Related CAPEC pattern: [object Object].
Related weaknesses· 1
MITRE ATT&CK crosswalk· 2
Related attack patterns· 1
Exploits1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Access Controlcwe-284 | 100% | live |
Related to2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Terminal Services DLLt1505.005 | 100% | live |
| SubTechnique | Accessibility Featurest1546.008 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.