Detailedlikelihood: Lowseverity: MediumDraft
CAPEC-649Adding a Space to a File Extension
Abstraction
Detailed
Status
Draft
Likelihood
Low
Severity
Medium
Description
An adversary adds a space character to the end of a file extension and takes advantage of an application that does not properly neutralize trailing special elements in file names. This extra space, which can be difficult for a user to notice, affects which default application is used to operate on the file and can be leveraged by the adversary to control execution.
Related weaknesses· 1
MITRE ATT&CK crosswalk· 1
Related attack patterns· 1
Exploits1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Path Equivalence: 'filename ' (Trailing Space)cwe-46 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Space after Filenamet1036.006 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.