Compliance Node Overview
MITRE CAPEC-23 (File Content Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary poisons files with a malicious payload (targeting the file systems accessible by the target software), which may be passed through by standard channels such as via email, and standard web content like PDF and multimedia files. The adversary exploits known vulnerabilities or handling routines in the target processes, in order to exploit the host's trust in executing remote content, including binary files. Likelihood of attack: High. Typical severity: Very High. Parent pattern for CAPEC-44 Overflow Binary Resource File. Maps to weaknesses CWE-20.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/23.html
SHA-256 integrity: be1a6256b33c3a2de5c5b310f24d51f686f7f8c5ae53ab81c7bbace0ec0db9ff
Primary Citations — 7 traced to source
- MITRE CAPEC-23: File Content Injection (https://capec.mitre.org/data/definitions/23.html)
- CWE-20: underlying weakness (http://cwe.mitre.org/data/definitions/20.html)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.