Skip to content

Confusing references to locations in software exploitation threats #290

Description

@mike1813

Threats H.M.HmACPAC.4 and P.L.HPAC.4 represent privilege escalation having succeeded in accessing vulnerable code in a Process. One threat deals with privilege escalation to gain admin rights on the Process Host, and the other to gain local user rights of the Process on its Host.

In both cases, the exploitation phase is confined to the same context(s) in which the attacker was able to access the vulnerability. If the attacker can access vulnerable code when the Host is in a specific location (e.g., by attacking it via a network to which it is then connected), then they can't gain privileges through the exploit when the Host is in another location. This is handled by channelling threat causes and effects through inferred local context assets associated with each location.

The issue here is that the threat description refers only to a space and not to a context. This seems confusing and should be fixed.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions