Remediate detected vulnerabilities in software through processes and tooling on a monthly, or more frequent, basis, based on the remediation process.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1602 | Data from Configuration Repository |
Comments
When known vulnerabilities affect network-device software, system images, or management components that expose configuration repositories, applying patches or supported software upgrades removes those weaknesses and reduces vulnerability dependent access to configuration data.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1602.001 | SNMP (MIB Dump) |
Comments
When known vulnerabilities affect SNMP-enabled network-device software or system images, applying patches or supported software upgrades removes those weaknesses and reduces opportunities to collect MIB data through vulnerable implementations.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1602.002 | Network Device Configuration Dump |
Comments
When known vulnerabilities affect network-device software or system images used to expose or retrieve device configurations, applying patches or supported software upgrades removes those weaknesses and reduces exploit-based opportunities to obtain configuration data.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1068 | Exploitation for Privilege Escalation |
Comments
Remediating known vulnerabilities in kernels, drivers, services, and privileged applications directly removes exploit paths that adversaries could use to obtain elevated privileges. This does not prevent exploitation of unknown vulnerabilities or weaknesses that remain outside the remediation scope.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1189 | Drive-by Compromise |
Comments
Remediating detected vulnerabilities in browsers, plug-ins, and other client software reduces successful exploitation when users visit malicious or compromised websites. This does not prevent drive-by activity that relies on zero-day vulnerabilities, social engineering, or malicious content that does not require exploitation.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1190 | Exploit Public-Facing Application |
Comments
Correcting identified vulnerabilities in internet-facing applications, services, and appliances directly removes known initial-access paths. Remediation may include patching, upgrading, replacing, disabling, or isolating the vulnerable component.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1203 | Exploitation for Client Execution |
Comments
Remediating known vulnerabilities in browsers, Office products, PDF readers, and other client applications reduces successful exploit-based code execution. This does not prevent exploitation of unknown vulnerabilities or unremediated unsupported software.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1210 | Exploitation of Remote Services |
Comments
Patching or otherwise correcting vulnerabilities in remotely reachable services removes known lateral-movement and remote-execution paths.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1211 | Exploitation for Stealth |
Comments
Remediation can remove vulnerabilities in operating systems, applications, security tools, and logging components that adversaries could exploit to conceal activity or impair visibility. This relationship applies only when the stealth behavior depends on an identified vulnerability.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1212 | Exploitation for Credential Access |
Comments
Correcting vulnerabilities in authentication systems, credential-handling software, kernels, and related components prevents exploit-based access to credentials.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1611 | Escape to Host |
Comments
Remediating vulnerabilities in host kernels, hypervisors, and container runtimes reduces successful container or virtual-machine escape. This does not prevent escapes caused solely by unsafe configuration, privileged containers, or exposed management sockets.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1495 | Firmware Corruption |
Comments
Applying BIOS, UEFI, device, and component firmware updates can remove vulnerabilities that permit unauthorized firmware modification or corruption. Other protections are still required against adversaries that already possess authorized firmware-update capability.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1542 | Pre-OS Boot |
Comments
This is a partial parent mapping because remediation of vulnerable BIOS, UEFI, and component firmware can remove known pre-OS exploitation paths. Other pre-OS persistence methods may require boot-integrity, signing, and hardware-root-of-trust controls.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1542.001 | System Firmware |
Comments
Applying current BIOS and UEFI updates directly remediates known system-firmware vulnerabilities that could enable persistence or execution below the operating system.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1542.002 | Component Firmware |
Comments
Firmware updates for storage devices, controllers, network adapters, and other components remove known vulnerabilities that could allow malicious component-level persistence or modification.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1548 | Abuse Elevation Control Mechanism |
Comments
This is a partial parent mapping because remediation can remove known vulnerabilities and implementation weaknesses used to bypass elevation controls.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1548.002 | Bypass User Account Control |
Comments
Applying current Windows security updates and supported platform upgrades removes known UAC-bypass and auto-elevation weaknesses. This does not prevent every UAC bypass or activity performed by an account that already has administrative privileges.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1546 | Event Triggered Execution |
Comments
Remediation can remove specific vulnerable event-triggered execution mechanisms, including known AppInit DLL and Application Shimming behaviors. Most event-triggered persistence also depends on configuration and permissions.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1546.010 | AppInit DLLs |
Comments
Upgrading or patching affected Windows platforms removes older AppInit DLL behaviors and weaknesses that adversaries could abuse for persistence or execution. Configuration controls remain necessary where the feature is still supported.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1546.011 | Application Shimming |
Comments
Applying the relevant Windows security updates removes known auto-elevation behavior associated with application-shim installation. Remediation does not prevent all shim abuse by an adversary that already has sufficient privileges.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1552 | Unsecured Credentials |
Comments
Remediation can correct specific software weaknesses that store credentials insecurely, including the Group Policy Preferences implementation. Most unsecured credential exposures require separate configuration, access-control, or secret-management controls.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1552.006 | Group Policy Preferences |
Comments
Applying the applicable Microsoft security update prevents newly configured Group Policy Preferences from storing credentials in a recoverable form. Previously stored credentials may still require separate identification, removal, and rotation.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1550.002 | Pass the Hash |
Comments
Applying relevant Windows security updates can restrict default remote access available to local administrator accounts and reduce some pass-the-hash activity. Remediation does not eliminate hash theft, NTLM use, or pass-the-hash through accounts that retain applicable privileges.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1574 | Hijack Execution Flow |
Comments
Remediation can correct vulnerable library-loading behavior and unsafe execution paths in affected software. Many other execution-flow hijacking methods depend on writable paths, permissions, or configuration rather than a software vulnerability.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1574.001 | DLL |
Comments
Vendor patches can correct unsafe DLL search paths, missing library references, and other side-loading conditions that allow an adversary-controlled DLL to execute. This does not prevent DLL hijacking in unsupported software.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1072 | Software Deployment Tools |
Comments
Remediating vulnerabilities in centralized software-deployment and endpoint-management products prevents exploit-based privileged access and enterprise-wide remote execution. This does not prevent abuse through stolen administrator credentials or legitimate product functionality.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1137 | Office Application Startup |
Comments
This is a partial parent mapping because product remediation can restrict specific Outlook startup and persistence mechanisms, including Outlook Forms, Home Page, and Rules. Other Office startup methods may require configuration and application-control safeguards.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1137.003 | Outlook Forms |
Comments
Applying current Outlook security updates can disable or restrict custom forms that adversaries may abuse for persistence and execution. Unsupported or unpatched Outlook installations remain exposed.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1137.004 | Outlook Home Page |
Comments
Applying the relevant Outlook updates removes or restricts the legacy Home Page functionality used to load malicious content when a folder is accessed.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1137.005 | Outlook Rules |
Comments
Applying current Outlook updates reduces abuse of rule-triggered execution mechanisms. This does not prevent all malicious mailbox-rule activity or activity performed through valid cloud-account access.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1555 | Credentials from Password Stores |
Comments
Remediation can correct vulnerabilities in browsers, password managers, and other credential-storage applications. It does not address every operating-system, application, or cloud credential store.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1555.003 | Credentials from Web Browsers |
Comments
Correcting identified browser vulnerabilities reduces exploit-based extraction of stored passwords, tokens, and other authentication data. This does not prevent theft by malware that already has sufficient access to the browser profile.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1555.005 | Password Managers |
Comments
Updating, upgrading, or replacing a vulnerable password-manager product removes known credential-exposure vulnerabilities. This does not prevent theft through a compromised master password, an unlocked vault, or an authorized session.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1539 | Steal Web Session Cookie |
Comments
Remediating vulnerabilities in browsers and related applications reduces exploit-based extraction of session cookies. This does not prevent cookie theft by malware or an adversary that already has sufficient access to browser storage or memory.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1686.002 | Network Device Firewall |
Comments
Applying security patches or supported software upgrades to vulnerable firewall appliances and network-device operating environments reduces exploit-based modification or disabling of firewall policy. This does not prevent changes made with valid administrative access.
References
|