Compliance Node Overview
MITRE CAPEC-35 (Leverage Executable Code in Non-Executable Files) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attack of this type exploits a system's trust in configuration and resource files. When the executable loads the resource (such as an image file or configuration file) the attacker has modified the file to either execute malicious code directly or manipulate the target process (e.g. application server) to execute based on the malicious configuration parameters. Likelihood of attack: High. Typical severity: Very High. Maps to weaknesses CWE-94, CWE-96, CWE-95, CWE-97, and others. Relates to MITRE ATT&CK T1027.006, T1027.009, T1564.009.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/35.html
SHA-256 integrity: 9d65a19702c37379398f5e8959a0c8d1b9ed686cd7b300f4495d7425f605ac0f
Primary Citations — 13 traced to source
- MITRE CAPEC-35: Leverage Executable Code in Non-Executable Files (https://capec.mitre.org/data/definitions/35.html)
- CWE-94: underlying weakness (http://cwe.mitre.org/data/definitions/94.html)
+ 11 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.