Standardseverity: HighDraft
CAPEC-635Alternative Execution Due to Deceptive Filenames
Abstraction
Standard
Status
Draft
Severity
High
Description
The extension of a file name is often used in various contexts to determine the application that is used to open and use it. If an attacker can cause an alternative application to be used, it may be able to execute malicious code, cause a denial of service or expose sensitive information.
Metadata: standard CAPEC pattern, status draft, severity high. Underlying weakness: CWE-162. Mapped ATT&CK technique: [object Object]. Related CAPEC pattern: [object Object].
Related weaknesses· 1
MITRE ATT&CK crosswalk· 1
Related attack patterns· 1
Exploits1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Neutralization of Trailing Special Elementscwe-162 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Double File Extensiont1036.007 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.