CIS Controls CIS-7.7

Remediate detected vulnerabilities in software through processes and tooling on a monthly, or more frequent, basis, based on the remediation process.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1602 Data from Configuration Repository
Comments
When known vulnerabilities affect network-device software, system images, or management components that expose configuration repositories, applying patches or supported software upgrades removes those weaknesses and reduces vulnerability dependent access to configuration data.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1602.001 SNMP (MIB Dump)
Comments
When known vulnerabilities affect SNMP-enabled network-device software or system images, applying patches or supported software upgrades removes those weaknesses and reduces opportunities to collect MIB data through vulnerable implementations.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1602.002 Network Device Configuration Dump
Comments
When known vulnerabilities affect network-device software or system images used to expose or retrieve device configurations, applying patches or supported software upgrades removes those weaknesses and reduces exploit-based opportunities to obtain configuration data.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1068 Exploitation for Privilege Escalation
Comments
Remediating known vulnerabilities in kernels, drivers, services, and privileged applications directly removes exploit paths that adversaries could use to obtain elevated privileges. This does not prevent exploitation of unknown vulnerabilities or weaknesses that remain outside the remediation scope.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1189 Drive-by Compromise
Comments
Remediating detected vulnerabilities in browsers, plug-ins, and other client software reduces successful exploitation when users visit malicious or compromised websites. This does not prevent drive-by activity that relies on zero-day vulnerabilities, social engineering, or malicious content that does not require exploitation.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1190 Exploit Public-Facing Application
Comments
Correcting identified vulnerabilities in internet-facing applications, services, and appliances directly removes known initial-access paths. Remediation may include patching, upgrading, replacing, disabling, or isolating the vulnerable component.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1203 Exploitation for Client Execution
Comments
Remediating known vulnerabilities in browsers, Office products, PDF readers, and other client applications reduces successful exploit-based code execution. This does not prevent exploitation of unknown vulnerabilities or unremediated unsupported software.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1210 Exploitation of Remote Services
Comments
Patching or otherwise correcting vulnerabilities in remotely reachable services removes known lateral-movement and remote-execution paths.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1211 Exploitation for Stealth
Comments
Remediation can remove vulnerabilities in operating systems, applications, security tools, and logging components that adversaries could exploit to conceal activity or impair visibility. This relationship applies only when the stealth behavior depends on an identified vulnerability.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1212 Exploitation for Credential Access
Comments
Correcting vulnerabilities in authentication systems, credential-handling software, kernels, and related components prevents exploit-based access to credentials.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1611 Escape to Host
Comments
Remediating vulnerabilities in host kernels, hypervisors, and container runtimes reduces successful container or virtual-machine escape. This does not prevent escapes caused solely by unsafe configuration, privileged containers, or exposed management sockets.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1495 Firmware Corruption
Comments
Applying BIOS, UEFI, device, and component firmware updates can remove vulnerabilities that permit unauthorized firmware modification or corruption. Other protections are still required against adversaries that already possess authorized firmware-update capability.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1542 Pre-OS Boot
Comments
This is a partial parent mapping because remediation of vulnerable BIOS, UEFI, and component firmware can remove known pre-OS exploitation paths. Other pre-OS persistence methods may require boot-integrity, signing, and hardware-root-of-trust controls.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1542.001 System Firmware
Comments
Applying current BIOS and UEFI updates directly remediates known system-firmware vulnerabilities that could enable persistence or execution below the operating system.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1542.002 Component Firmware
Comments
Firmware updates for storage devices, controllers, network adapters, and other components remove known vulnerabilities that could allow malicious component-level persistence or modification.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1548 Abuse Elevation Control Mechanism
Comments
This is a partial parent mapping because remediation can remove known vulnerabilities and implementation weaknesses used to bypass elevation controls.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1548.002 Bypass User Account Control
Comments
Applying current Windows security updates and supported platform upgrades removes known UAC-bypass and auto-elevation weaknesses. This does not prevent every UAC bypass or activity performed by an account that already has administrative privileges.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1546 Event Triggered Execution
Comments
Remediation can remove specific vulnerable event-triggered execution mechanisms, including known AppInit DLL and Application Shimming behaviors. Most event-triggered persistence also depends on configuration and permissions.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1546.010 AppInit DLLs
Comments
Upgrading or patching affected Windows platforms removes older AppInit DLL behaviors and weaknesses that adversaries could abuse for persistence or execution. Configuration controls remain necessary where the feature is still supported.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1546.011 Application Shimming
Comments
Applying the relevant Windows security updates removes known auto-elevation behavior associated with application-shim installation. Remediation does not prevent all shim abuse by an adversary that already has sufficient privileges.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1552 Unsecured Credentials
Comments
Remediation can correct specific software weaknesses that store credentials insecurely, including the Group Policy Preferences implementation. Most unsecured credential exposures require separate configuration, access-control, or secret-management controls.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1552.006 Group Policy Preferences
Comments
Applying the applicable Microsoft security update prevents newly configured Group Policy Preferences from storing credentials in a recoverable form. Previously stored credentials may still require separate identification, removal, and rotation.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1550.002 Pass the Hash
Comments
Applying relevant Windows security updates can restrict default remote access available to local administrator accounts and reduce some pass-the-hash activity. Remediation does not eliminate hash theft, NTLM use, or pass-the-hash through accounts that retain applicable privileges.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1574 Hijack Execution Flow
Comments
Remediation can correct vulnerable library-loading behavior and unsafe execution paths in affected software. Many other execution-flow hijacking methods depend on writable paths, permissions, or configuration rather than a software vulnerability.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1574.001 DLL
Comments
Vendor patches can correct unsafe DLL search paths, missing library references, and other side-loading conditions that allow an adversary-controlled DLL to execute. This does not prevent DLL hijacking in unsupported software.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1072 Software Deployment Tools
Comments
Remediating vulnerabilities in centralized software-deployment and endpoint-management products prevents exploit-based privileged access and enterprise-wide remote execution. This does not prevent abuse through stolen administrator credentials or legitimate product functionality.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1137 Office Application Startup
Comments
This is a partial parent mapping because product remediation can restrict specific Outlook startup and persistence mechanisms, including Outlook Forms, Home Page, and Rules. Other Office startup methods may require configuration and application-control safeguards.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1137.003 Outlook Forms
Comments
Applying current Outlook security updates can disable or restrict custom forms that adversaries may abuse for persistence and execution. Unsupported or unpatched Outlook installations remain exposed.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1137.004 Outlook Home Page
Comments
Applying the relevant Outlook updates removes or restricts the legacy Home Page functionality used to load malicious content when a folder is accessed.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1137.005 Outlook Rules
Comments
Applying current Outlook updates reduces abuse of rule-triggered execution mechanisms. This does not prevent all malicious mailbox-rule activity or activity performed through valid cloud-account access.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1555 Credentials from Password Stores
Comments
Remediation can correct vulnerabilities in browsers, password managers, and other credential-storage applications. It does not address every operating-system, application, or cloud credential store.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1555.003 Credentials from Web Browsers
Comments
Correcting identified browser vulnerabilities reduces exploit-based extraction of stored passwords, tokens, and other authentication data. This does not prevent theft by malware that already has sufficient access to the browser profile.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1555.005 Password Managers
Comments
Updating, upgrading, or replacing a vulnerable password-manager product removes known credential-exposure vulnerabilities. This does not prevent theft through a compromised master password, an unlocked vault, or an authorized session.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1539 Steal Web Session Cookie
Comments
Remediating vulnerabilities in browsers and related applications reduces exploit-based extraction of session cookies. This does not prevent cookie theft by malware or an adversary that already has sufficient access to browser storage or memory.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1686.002 Network Device Firewall
Comments
Applying security patches or supported software upgrades to vulnerable firewall appliances and network-device operating environments reduces exploit-based modification or disabling of firewall policy. This does not prevent changes made with valid administrative access.
References