Threats H.M.HmACPAC.4 and P.L.HPAC.4 represent privilege escalation having succeeded in accessing vulnerable code in a Process. One threat deals with privilege escalation to gain admin rights on the Process Host, and the other to gain local user rights of the Process on its Host.
In both cases, the exploitation phase is confined to the same context(s) in which the attacker was able to access the vulnerability. If the attacker can access vulnerable code when the Host is in a specific location (e.g., by attacking it via a network to which it is then connected), then they can't gain privileges through the exploit when the Host is in another location. This is handled by channelling threat causes and effects through inferred local context assets associated with each location.
The issue here is that the threat description refers only to a space and not to a context. This seems confusing and should be fixed.
Threats H.M.HmACPAC.4 and P.L.HPAC.4 represent privilege escalation having succeeded in accessing vulnerable code in a Process. One threat deals with privilege escalation to gain admin rights on the Process Host, and the other to gain local user rights of the Process on its Host.
In both cases, the exploitation phase is confined to the same context(s) in which the attacker was able to access the vulnerability. If the attacker can access vulnerable code when the Host is in a specific location (e.g., by attacking it via a network to which it is then connected), then they can't gain privileges through the exploit when the Host is in another location. This is handled by channelling threat causes and effects through inferred local context assets associated with each location.
The issue here is that the threat description refers only to a space and not to a context. This seems confusing and should be fixed.