CWE-506

Embedded Malicious Code

High

Description

The product contains code that appears to be malicious in nature.

Potential Impact

How to Fix

Testing

Remove the malicious code and start an effort to ensure that no more malicious code exists. This may require a detailed review of all code, as it is possible to hide a serious attack in only one or two lines of code. These lines may be located almost anywhere in an application and may have been intentionally obfuscated by the attacker.

Detection Methods

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-506 vulnerabilities in your codebase.

Get Security Assessment