Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-635 — Alternative Execution Due to Deceptive Filenames
CAPEC-635

Alternative Execution Due to Deceptive Filenames

TLP:CLEAR

Description

Typical severity: High. The extension of a file name is often used in various contexts to determine the application that is used to open and use it. If an attacker can cause an alternative application to be used, it may be able to execute malicious code, cause a denial of service or expose sensitive information.

Mitigation

Applications should insure that the content of the file is consistent with format it is expecting, and not depend solely on the file extension.

Details

Platforms
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.