Standardlikelihood: Mediumseverity: HighDraft
CAPEC-701Browser in the Middle (BiTM)
Abstraction
Standard
Status
Draft
Likelihood
Medium
Severity
High
Description
An adversary exploits the inherent functionalities of a web browser, in order to establish an unnoticed remote desktop connection in the victim's browser to the adversary's system. The adversary must deploy a web client with a remote desktop session that the victim can access.
Metadata: standard CAPEC pattern, status draft, likelihood medium, severity high. Underlying weaknesses: CWE-294, CWE-345. Related CAPEC patterns: [object Object], [object Object], [object Object], [object Object].
Related weaknesses· 2
Related attack patterns· 4
Exploits2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Insufficient Verification of Data Authenticitycwe-345 | 100% | live |
| Weakness | Authentication Bypass by Capture-replaycwe-294 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.