Umbra Wiki weakness weakness/CWE-507
Back to wiki

CWE-507 — Trojan Horse

provenance: imported · CWE: CWE-507

CWE-507: Trojan Horse

MITRE CWE weakness

Kind Weakness
Abstraction Base
Status Incomplete
Likelihood of exploit

Description

The product appears to contain benign or useful functionality, but it also contains code that is hidden from normal operation that violates the intended security policy of the user or the system administrator.

Common consequences

  • Confidentiality, Integrity, Availability: Execute Unauthorized Code or Commands

Mitigations

Operation — Most antivirus software scans for Trojan Horses.

Installation — Verify the integrity of the product that is being installed.

References

  • CWE page: https://cwe.mitre.org/data/definitions/507.html
  • CWE list: https://cwe.mitre.org/data/index.html