King of Elevation of Privilege I
An attacker can inject a command that the system will run at a higher privilege level.
Threat |
|
Your application server is launched with an admin user account instead of with a service account and an attacker manages to inject a command that is run in the operating system (OS) as the admin user. |
|
CAPEC |
CAPEC-233 – Privilege escalation CAPEC-69 – Target programs with elevated privileges |
ASVS |
1.2.1 – Ensure you’re not using service accounts with only the permissions they need 2.10.2 – Ensure service to service auth is not performed as root |
CWE |
CWE-250 – Execution with unnecessary privileges CWE-78 – Improper neutralization... |