Umbra Wiki attack-pattern attack-pattern/CAPEC-253
Back to wiki

CAPEC-253 — Remote Code Inclusion

provenance: imported · CWE: CWE-829

CAPEC-253: Remote Code Inclusion

MITRE CAPEC attack pattern

Status Draft
Typical severity
Likelihood of attack
Catalogue CAPEC 3.9 (2023-01-24)

Description

The attacker forces an application to load arbitrary code files from a remote location. The attacker could use this to try to load old versions of library files that have known vulnerabilities, to load malicious files that the attacker placed on the remote machine, or to otherwise change the functionality of the targeted application in unexpected ways.

Where this sits in the chain

A finding maps to a weakness (CWE), a weakness is exploited by an attack pattern (CAPEC), and an attack pattern shows up in ATT&CK as observed adversary behaviour. This page is the middle hop.

Weaknesses exploited: CWE-829

Prerequisites

  • Target application server must allow remote files to be included.The malicious file must be placed on the remote machine previously.

Mitigations

  • Minimize attacks by input validation and sanitization of any user data that will be used by the target application to locate a remote file to be included.

Source