CAPEC-480: Escaping Virtualization

ID CAPEC-480
Typical Severity Very High
Likelihood Of Attack Low
Status Draft

An adversary gains access to an application, service, or device with the privileges of an authorized or privileged user by escaping the confines of a virtualized environment. The adversary is then able to access resources or execute unauthorized code within the host environment, generally with the privileges of the user running the virtualized process. Successfully executing an attack of this type is often the first step in executing more complex attacks.

https://capec.mitre.org/data/definitions/480.html

Weaknesses

# ID Name Type
CWE-693 Protection Mechanism Failure weakness

Taxonomiy Mapping

Type # ID Name
ATTACK 1611 Escape to Host
Loading...