Compliance Node Overview
MITRE CAPEC-635 (Alternative Execution Due to Deceptive Filenames) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. The extension of a file name is often used in various contexts to determine the application that is used to open and use it. If an attacker can cause an alternative application to be used, it may be able to execute malicious code, cause a denial of service or expose sensitive information. Likelihood of attack: Unknown. Typical severity: High. Parent pattern for CAPEC-11 Cause Web Server Misclassification; CAPEC-649 Adding a Space to a File Extension. Maps to weaknesses CWE-162. Relates to MITRE ATT&CK T1036.007.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/635.html
SHA-256 integrity: 906cf515204b8b84833248f370568fe1e753720ea424fa64b11a2d2e0db48b15
Primary Citations — 9 traced to source
- MITRE CAPEC-635: Alternative Execution Due to Deceptive Filenames (https://capec.mitre.org/data/definitions/635.html)
- CWE-162: underlying weakness (http://cwe.mitre.org/data/definitions/162.html)
+ 7 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.