CAPEC 669 Alteration of a Software Update

Draft Standard Medium Risk
Severity High

Description

{'xhtml:p': 'An adversary with access to an organization\u00e2\u0080\u0099s software update infrastructure inserts malware into the content of an outgoing update to fielded systems where a wide range of malicious effects are possible. With the same level of access, the adversary can alter a software update to perform specific malicious acts including granting the adversary control over the software\u00e2\u0080\u0099s normal functionality.'}

Attack Execution Flow

3

Mitigations

2

Consequences

Relationships

Related ATT&CK Techniques

1