Perform application updates on enterprise assets through automated patch management on a monthly, or more frequent, basis.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1189 | Drive-by Compromise |
Comments
Automated application patching keeps browsers and browser plug-ins current, removing known vulnerabilities that malicious or compromised websites could exploit for client execution. The safeguard does not prevent drive-by attacks relying on zero-day vulnerabilities, social engineering, or malicious browser notifications.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1190 | Exploit Public-Facing Application |
Comments
Automated application patching removes known vulnerabilities from externally exposed web applications, databases, VPN products, management platforms, and other application services. It does not correct insecure configurations, unsupported custom code, or vulnerabilities for which no vendor patch exists.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1203 | Exploitation for Client Execution |
Comments
Applying current security updates to browsers, Office products, PDF readers, and other client applications reduces successful exploitation of known application vulnerabilities. Operating-system vulnerabilities and unknown application vulnerabilities require separate protections.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1072 | Software Deployment Tools |
Comments
Patching centralized deployment and endpoint-management applications removes known vulnerabilities that could provide adversaries with privileged access or enterprise-wide remote execution. The safeguard does not prevent abuse through stolen administrator credentials or legitimate product functionality.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1137.003 | Outlook Forms |
Comments
Applying current Outlook security updates can disable or restrict custom forms that adversaries may abuse for persistence and execution. The safeguard does not prevent all malicious Office content or abuse of an unpatched or unsupported Outlook installation.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1137.004 | Outlook Home Page |
Comments
Outlook application updates remove or restrict the legacy Home Page feature used to load malicious content when a folder is accessed. The relationship depends on deploying the relevant Outlook security updates.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1137.005 | Outlook Rules |
Comments
Applying current Outlook patches reduces abuse of rule-triggered Visual Basic and related persistence mechanisms. It does not prevent all malicious mailbox-rule activity or activity performed through valid cloud-account access.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1555.003 | Credentials from Web Browsers |
Comments
Automated browser updates remove known vulnerabilities that could expose stored passwords, tokens, or browser authentication data. Patching does not prevent credential theft by malware already executing with sufficient access to the browser profile.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1555.005 | Password Managers |
Comments
Automated updates to password-manager applications remove known vulnerabilities that could expose stored or decrypted credentials.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1574.001 | DLL |
Comments
Applying vendor patches to vulnerable applications can correct unsafe DLL search paths, missing library references, and other side-loading conditions that allow an adversary-controlled DLL to execute. It does not prevent DLL hijacking in unpatched software or through writable application directories.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1068 | Exploitation for Privilege Escalation |
Comments
Application patching removes known vulnerabilities in privileged applications, agents, services, and third-party drivers that could allow escalation of privileges. Operating-system and kernel vulnerabilities are addressed separately through operating-system patch management.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1210 | Exploitation of Remote Services |
Comments
Application patching removes known vulnerabilities from third-party database, web, virtualization, file-transfer, remote-management, and similar services used for lateral movement. Vulnerabilities in operating-system-supplied remote services require operating-system patching.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1211 | Exploitation for Stealth |
Comments
Updating applications and security products can remove known vulnerabilities that adversaries could exploit to conceal activity or impair application-level visibility. Operating-system and kernel implementations are outside this safeguard's application scope.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1212 | Exploitation for Credential Access |
Comments
Application patching removes known vulnerabilities in authentication products, browsers, identity applications, network-management products, and other credential-handling software. Vulnerabilities in operating-system authentication components require operating-system patching.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1137 | Office Application Startup |
Comments
Application patches can restrict specific Outlook startup and persistence mechanisms, including Outlook Forms, Home Page, and Rules. Other Office startup mechanisms that rely on macros, add-ins, templates, or configuration changes are not necessarily prevented by patching.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1555 | Credentials from Password Stores |
Comments
Application patching can remove browser and password-manager vulnerabilities used to extract stored credentials. Operating-system credential stores and cloud secrets platforms may require different update mechanisms.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1574 | Hijack Execution Flow |
Comments
Application updates can correct unsafe DLL search paths and other software defects that permit DLL side-loading. Most other execution-flow hijacking implementations require permissions, application control, or operating-system configuration protections.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1176 | Software Extensions |
Comments
Updating browsers and IDEs can remove insecure extension mechanisms, but it does not prevent a user or adversary from installing an otherwise permitted malicious extension.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1176.001 | Browser Extensions |
Comments
Automated browser updates can remove deprecated extension-loading mechanisms and strengthen extension permission and installation controls. Extension allowlisting and trusted-source restrictions remain necessary to prevent malicious extensions.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1176.002 | IDE Extensions |
Comments
Updating IDE applications can correct vulnerabilities in extension loading and provide improved extension security controls. The safeguard does not independently prevent installation of a malicious or compromised extension from an approved marketplace.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1539 | Steal Web Session Cookie |
Comments
Updating browsers, password managers, and related applications reduces exploitation of known vulnerabilities used to extract session cookies. It does not prevent cookie theft by malware or an adversary that already has sufficient access to browser storage or memory.
References
|