4. of Elevation of Privilege (2022 deck)
An attacker can escape from a container or other sandbox.
Threat |
|
You are using the public cloud or are running your application on a multi-tenant environment (a physical computer shared between multiple organizations, running multiple virtual machines (VMs) or software for each of them); an attacker is running in another VM or container on the same environment and is able to break out of their hypervisor or container and attack other tenants. |
|
CAPEC |
CAPEC-480 – Escaping virtualization CAPEC-233 – Privilege escalation |
ASVS |
N/A |
CWE |
CWE-668 – Exposure of resources to the wrong sphere |
... |