attack-patternCAPEC-669
Alteration of a Software Update
An adversary with access to an organization’s software update infrastructure inserts malware into the content of an outgoing update to fielded systems where a wide range of malicious effects are possible. With the same level of access, the adversary can alter a software update to perform specific malicious acts including granting the adversary control over the software’s normal functionality.
Typical severity
High
Likelihood of attack
Medium
Classification
Summary
Details
Prerequisites
Summary
Details
Execution flow
Summary
Details