What MITRE ATT&CK T1574.005: Executable Installer File Permissions Weakness (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation / TA0005 - Defense Evasion) requires
MITRE ATT&CK T1574.005 (Executable Installer File Permissions Weakness) is an Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking the binaries used by an installer. These processes may automatically execute specific binaries as part of their functionality or to perform other actions. If the permissions on the file system directory containing a target binary, or permissions on the binary itself, are improperly set, then the target binary may be overwritten with another binary using user-level permissions and executed by the original process. Affected platforms: Windows. MITRE-documented mitigations include M1047 Audit, M1052 User Account Control, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, CA-07, CM-02, CM-05.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1574/005/
SHA-256 integrity: e7dc65ac070a776937b5c61063c98f308bcddf068311360fb648f8a7f759b65a
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1574.005: Executable Installer File Permissions Weakness (https://attack.mitre.org/techniques/T1574/005/)
- MITRE ATT&CK Tactic TA0003: Persistence (https://attack.mitre.org/tactics/TA0003/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access