CIS Controls CIS-7.4

Perform application updates on enterprise assets through automated patch management on a monthly, or more frequent, basis.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-7.4 Perform Automated Application Patch Management mitigates T1189 Drive-by Compromise
Comments
Automated application patching keeps browsers and browser plug-ins current, removing known vulnerabilities that malicious or compromised websites could exploit for client execution. The safeguard does not prevent drive-by attacks relying on zero-day vulnerabilities, social engineering, or malicious browser notifications.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1190 Exploit Public-Facing Application
Comments
Automated application patching removes known vulnerabilities from externally exposed web applications, databases, VPN products, management platforms, and other application services. It does not correct insecure configurations, unsupported custom code, or vulnerabilities for which no vendor patch exists.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1203 Exploitation for Client Execution
Comments
Applying current security updates to browsers, Office products, PDF readers, and other client applications reduces successful exploitation of known application vulnerabilities. Operating-system vulnerabilities and unknown application vulnerabilities require separate protections.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1072 Software Deployment Tools
Comments
Patching centralized deployment and endpoint-management applications removes known vulnerabilities that could provide adversaries with privileged access or enterprise-wide remote execution. The safeguard does not prevent abuse through stolen administrator credentials or legitimate product functionality.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1137.003 Outlook Forms
Comments
Applying current Outlook security updates can disable or restrict custom forms that adversaries may abuse for persistence and execution. The safeguard does not prevent all malicious Office content or abuse of an unpatched or unsupported Outlook installation.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1137.004 Outlook Home Page
Comments
Outlook application updates remove or restrict the legacy Home Page feature used to load malicious content when a folder is accessed. The relationship depends on deploying the relevant Outlook security updates.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1137.005 Outlook Rules
Comments
Applying current Outlook patches reduces abuse of rule-triggered Visual Basic and related persistence mechanisms. It does not prevent all malicious mailbox-rule activity or activity performed through valid cloud-account access.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1555.003 Credentials from Web Browsers
Comments
Automated browser updates remove known vulnerabilities that could expose stored passwords, tokens, or browser authentication data. Patching does not prevent credential theft by malware already executing with sufficient access to the browser profile.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1555.005 Password Managers
Comments
Automated updates to password-manager applications remove known vulnerabilities that could expose stored or decrypted credentials.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1574.001 DLL
Comments
Applying vendor patches to vulnerable applications can correct unsafe DLL search paths, missing library references, and other side-loading conditions that allow an adversary-controlled DLL to execute. It does not prevent DLL hijacking in unpatched software or through writable application directories.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1068 Exploitation for Privilege Escalation
Comments
Application patching removes known vulnerabilities in privileged applications, agents, services, and third-party drivers that could allow escalation of privileges. Operating-system and kernel vulnerabilities are addressed separately through operating-system patch management.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1210 Exploitation of Remote Services
Comments
Application patching removes known vulnerabilities from third-party database, web, virtualization, file-transfer, remote-management, and similar services used for lateral movement. Vulnerabilities in operating-system-supplied remote services require operating-system patching.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1211 Exploitation for Stealth
Comments
Updating applications and security products can remove known vulnerabilities that adversaries could exploit to conceal activity or impair application-level visibility. Operating-system and kernel implementations are outside this safeguard's application scope.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1212 Exploitation for Credential Access
Comments
Application patching removes known vulnerabilities in authentication products, browsers, identity applications, network-management products, and other credential-handling software. Vulnerabilities in operating-system authentication components require operating-system patching.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1137 Office Application Startup
Comments
Application patches can restrict specific Outlook startup and persistence mechanisms, including Outlook Forms, Home Page, and Rules. Other Office startup mechanisms that rely on macros, add-ins, templates, or configuration changes are not necessarily prevented by patching.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1555 Credentials from Password Stores
Comments
Application patching can remove browser and password-manager vulnerabilities used to extract stored credentials. Operating-system credential stores and cloud secrets platforms may require different update mechanisms.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1574 Hijack Execution Flow
Comments
Application updates can correct unsafe DLL search paths and other software defects that permit DLL side-loading. Most other execution-flow hijacking implementations require permissions, application control, or operating-system configuration protections.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1176 Software Extensions
Comments
Updating browsers and IDEs can remove insecure extension mechanisms, but it does not prevent a user or adversary from installing an otherwise permitted malicious extension.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1176.001 Browser Extensions
Comments
Automated browser updates can remove deprecated extension-loading mechanisms and strengthen extension permission and installation controls. Extension allowlisting and trusted-source restrictions remain necessary to prevent malicious extensions.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1176.002 IDE Extensions
Comments
Updating IDE applications can correct vulnerabilities in extension loading and provide improved extension security controls. The safeguard does not independently prevent installation of a malicious or compromised extension from an approved marketplace.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1539 Steal Web Session Cookie
Comments
Updating browsers, password managers, and related applications reduces exploitation of known vulnerabilities used to extract session cookies. It does not prevent cookie theft by malware or an adversary that already has sufficient access to browser storage or memory.
References