usnistgov / mobile-threat-catalogue

NIST/NCCoE Mobile Threat Catalogue
https://pages.nist.gov/mobile-threat-catalogue
Other
142 stars 40 forks source link

Adding CVE's for MTC Category: Embedding malicious code within app in encrypted or obfuscated form, then decrypting or deobfuscating and executing at runtime to evade app vetting. #215

Closed cjones1 closed 7 years ago

cjones1 commented 7 years ago

General Comment

Threat ID: If the comment is specific to a given threat, provide the ID for that threat. Otherwise, leave this blank.

Type of Comment: T Enter the letter that best describes the nature of your comment

Proposed Change: Add CVE's to given MTC Category With as much detail as possible, what change should be made.

Justification: Need CVE's to be used as examples for this threat in the MTC. Provide reasoning as to why the proposed change is necessary. For technical comments, providing references to supporting sources is encouraged.