ZERO
Back
attack-patternCAPEC-669

Alteration of a Software Update

An adversary with access to an organization’s software update infrastructure inserts malware into the content of an outgoing update to fielded systems where a wide range of malicious effects are possible. With the same level of access, the adversary can alter a software update to perform specific malicious acts including granting the adversary control over the software’s normal functionality.

Typical severity
High
Likelihood of attack
Medium

Classification

Summary

Details

Prerequisites

Summary

Details

Execution flow

Summary

Details