Ensure only fully supported browsers and email clients are allowed to execute in the enterprise, only using the latest version of browsers and email clients provided through the vendor.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1212 | Exploitation for Credential Access |
Comments
Browsers and email clients are common targets for vulnerabilities. Requiring the latest vendor-supported versions directly reduces exposure to known client-software vulnerabilities.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1068 | Exploitation for Privilege Escalation |
Comments
Browsers and email clients are common targets for vulnerabilities. Requiring the latest vendor-supported versions directly reduces exposure to known client-software vulnerabilities.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1211 | Exploitation for Stealth |
Comments
Browsers and email clients are common targets for vulnerabilities. Requiring the latest vendor-supported versions directly reduces exposure to known client-software vulnerabilities.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1189 | Drive-by Compromise |
Comments
Fully supported, current browsers contain vendor patches and modern security features that reduce successful exploitation when users visit compromised or malicious websites.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1203 | Exploitation for Client Execution |
Comments
Browsers and email clients are common targets for vulnerabilities that provide adversary code execution. Requiring the latest vendor-supported versions directly reduces exposure to known client-software vulnerabilities.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1137.003 | Outlook Forms |
Comments
Current Outlook versions include vendor changes that restrict or warn about custom Outlook forms that may otherwise be abused for persistence and execution. The safeguard ensures those security updates are present.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1137.004 | Outlook Home Page |
Comments
Microsoft updates removed or restricted the legacy Outlook Home Page functionality used for persistence. Preventing obsolete Outlook versions from executing directly prevents continued access to older vulnerable implementations.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1137.005 | Outlook Rules |
Comments
Vendor patches address Outlook mechanisms that adversaries may use to establish rule-triggered persistence or execution. Requiring current supported Outlook versions ensures the relevant security changes are applied.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1689 | Downgrade Attack |
Comments
Allowing only the latest supported browser and email-client versions prevents adversaries or users from running obsolete versions that lack current protections. This directly reduces downgrade opportunities involving older, weaker software versions.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1137 | Office Application Startup |
Comments
This is a partial mapping because several sub-techniques specifically abuse Outlook features addressed by vendor patches. Other Office startup methods involving templates, test keys, and general add-ins are outside the browser-and-email-client scope.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1176.001 | Browser Extensions |
Comments
Current browsers incorporate newer extension permission models, security controls, and protections against outdated installation methods. This does not prevent users or adversaries from installing an otherwise permitted malicious extension.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1539 | Steal Web Session Cookie |
Comments
Updating browsers reduces the likelihood that known vulnerabilities can be exploited to extract cookies from browser storage or memory. It does not prevent malware with sufficient local access from directly reading cookies or browser data.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1555.003 | Credentials from Web Browsers |
Comments
Current browser versions reduce exploitation of known weaknesses that expose stored passwords and authentication data. Updating the browser does not prevent credential theft by malware already executing with access to the user's browser profile.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1176 | Software Extensions |
Comments
Keeping browsers current affects browser extensions.
References
|