CIS Controls Continuous Vulnerability Management Capability Group

Develop a plan to continuously assess and track vulnerabilities on all enterprise assets within the enterprise’s infrastructure, in order to remediate, and minimize, the window of opportunity for attackers. Monitor public and private industry sources for new threat and vulnerability information.

All Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1602 Data from Configuration Repository
Comments
When known vulnerabilities affect network-device software, system images, or management components that expose configuration repositories, applying patches or supported software upgrades removes those weaknesses and reduces vulnerability dependent access to configuration data.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1602.001 SNMP (MIB Dump)
Comments
When known vulnerabilities affect SNMP-enabled network-device software or system images, applying patches or supported software upgrades removes those weaknesses and reduces opportunities to collect MIB data through vulnerable implementations.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1602.002 Network Device Configuration Dump
Comments
When known vulnerabilities affect network-device software or system images used to expose or retrieve device configurations, applying patches or supported software upgrades removes those weaknesses and reduces exploit-based opportunities to obtain configuration data.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1068 Exploitation for Privilege Escalation
Comments
Remediating known vulnerabilities in kernels, drivers, services, and privileged applications directly removes exploit paths that adversaries could use to obtain elevated privileges. This does not prevent exploitation of unknown vulnerabilities or weaknesses that remain outside the remediation scope.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1189 Drive-by Compromise
Comments
Remediating detected vulnerabilities in browsers, plug-ins, and other client software reduces successful exploitation when users visit malicious or compromised websites. This does not prevent drive-by activity that relies on zero-day vulnerabilities, social engineering, or malicious content that does not require exploitation.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1190 Exploit Public-Facing Application
Comments
Correcting identified vulnerabilities in internet-facing applications, services, and appliances directly removes known initial-access paths. Remediation may include patching, upgrading, replacing, disabling, or isolating the vulnerable component.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1203 Exploitation for Client Execution
Comments
Remediating known vulnerabilities in browsers, Office products, PDF readers, and other client applications reduces successful exploit-based code execution. This does not prevent exploitation of unknown vulnerabilities or unremediated unsupported software.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1210 Exploitation of Remote Services
Comments
Patching or otherwise correcting vulnerabilities in remotely reachable services removes known lateral-movement and remote-execution paths.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1211 Exploitation for Stealth
Comments
Remediation can remove vulnerabilities in operating systems, applications, security tools, and logging components that adversaries could exploit to conceal activity or impair visibility. This relationship applies only when the stealth behavior depends on an identified vulnerability.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1212 Exploitation for Credential Access
Comments
Correcting vulnerabilities in authentication systems, credential-handling software, kernels, and related components prevents exploit-based access to credentials.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1611 Escape to Host
Comments
Remediating vulnerabilities in host kernels, hypervisors, and container runtimes reduces successful container or virtual-machine escape. This does not prevent escapes caused solely by unsafe configuration, privileged containers, or exposed management sockets.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1495 Firmware Corruption
Comments
Applying BIOS, UEFI, device, and component firmware updates can remove vulnerabilities that permit unauthorized firmware modification or corruption. Other protections are still required against adversaries that already possess authorized firmware-update capability.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1542 Pre-OS Boot
Comments
This is a partial parent mapping because remediation of vulnerable BIOS, UEFI, and component firmware can remove known pre-OS exploitation paths. Other pre-OS persistence methods may require boot-integrity, signing, and hardware-root-of-trust controls.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1542.001 System Firmware
Comments
Applying current BIOS and UEFI updates directly remediates known system-firmware vulnerabilities that could enable persistence or execution below the operating system.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1542.002 Component Firmware
Comments
Firmware updates for storage devices, controllers, network adapters, and other components remove known vulnerabilities that could allow malicious component-level persistence or modification.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1548 Abuse Elevation Control Mechanism
Comments
This is a partial parent mapping because remediation can remove known vulnerabilities and implementation weaknesses used to bypass elevation controls.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1548.002 Bypass User Account Control
Comments
Applying current Windows security updates and supported platform upgrades removes known UAC-bypass and auto-elevation weaknesses. This does not prevent every UAC bypass or activity performed by an account that already has administrative privileges.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1546 Event Triggered Execution
Comments
Remediation can remove specific vulnerable event-triggered execution mechanisms, including known AppInit DLL and Application Shimming behaviors. Most event-triggered persistence also depends on configuration and permissions.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1546.010 AppInit DLLs
Comments
Upgrading or patching affected Windows platforms removes older AppInit DLL behaviors and weaknesses that adversaries could abuse for persistence or execution. Configuration controls remain necessary where the feature is still supported.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1546.011 Application Shimming
Comments
Applying the relevant Windows security updates removes known auto-elevation behavior associated with application-shim installation. Remediation does not prevent all shim abuse by an adversary that already has sufficient privileges.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1552 Unsecured Credentials
Comments
Remediation can correct specific software weaknesses that store credentials insecurely, including the Group Policy Preferences implementation. Most unsecured credential exposures require separate configuration, access-control, or secret-management controls.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1552.006 Group Policy Preferences
Comments
Applying the applicable Microsoft security update prevents newly configured Group Policy Preferences from storing credentials in a recoverable form. Previously stored credentials may still require separate identification, removal, and rotation.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1550.002 Pass the Hash
Comments
Applying relevant Windows security updates can restrict default remote access available to local administrator accounts and reduce some pass-the-hash activity. Remediation does not eliminate hash theft, NTLM use, or pass-the-hash through accounts that retain applicable privileges.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1574 Hijack Execution Flow
Comments
Remediation can correct vulnerable library-loading behavior and unsafe execution paths in affected software. Many other execution-flow hijacking methods depend on writable paths, permissions, or configuration rather than a software vulnerability.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1574.001 DLL
Comments
Vendor patches can correct unsafe DLL search paths, missing library references, and other side-loading conditions that allow an adversary-controlled DLL to execute. This does not prevent DLL hijacking in unsupported software.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1072 Software Deployment Tools
Comments
Remediating vulnerabilities in centralized software-deployment and endpoint-management products prevents exploit-based privileged access and enterprise-wide remote execution. This does not prevent abuse through stolen administrator credentials or legitimate product functionality.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1137 Office Application Startup
Comments
This is a partial parent mapping because product remediation can restrict specific Outlook startup and persistence mechanisms, including Outlook Forms, Home Page, and Rules. Other Office startup methods may require configuration and application-control safeguards.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1137.003 Outlook Forms
Comments
Applying current Outlook security updates can disable or restrict custom forms that adversaries may abuse for persistence and execution. Unsupported or unpatched Outlook installations remain exposed.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1137.004 Outlook Home Page
Comments
Applying the relevant Outlook updates removes or restricts the legacy Home Page functionality used to load malicious content when a folder is accessed.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1137.005 Outlook Rules
Comments
Applying current Outlook updates reduces abuse of rule-triggered execution mechanisms. This does not prevent all malicious mailbox-rule activity or activity performed through valid cloud-account access.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1555 Credentials from Password Stores
Comments
Remediation can correct vulnerabilities in browsers, password managers, and other credential-storage applications. It does not address every operating-system, application, or cloud credential store.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1555.003 Credentials from Web Browsers
Comments
Correcting identified browser vulnerabilities reduces exploit-based extraction of stored passwords, tokens, and other authentication data. This does not prevent theft by malware that already has sufficient access to the browser profile.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1555.005 Password Managers
Comments
Updating, upgrading, or replacing a vulnerable password-manager product removes known credential-exposure vulnerabilities. This does not prevent theft through a compromised master password, an unlocked vault, or an authorized session.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1539 Steal Web Session Cookie
Comments
Remediating vulnerabilities in browsers and related applications reduces exploit-based extraction of session cookies. This does not prevent cookie theft by malware or an adversary that already has sufficient access to browser storage or memory.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1686.002 Network Device Firewall
Comments
Applying security patches or supported software upgrades to vulnerable firewall appliances and network-device operating environments reduces exploit-based modification or disabling of firewall policy. This does not prevent changes made with valid administrative access.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1189 Drive-by Compromise
Comments
Automated application patching keeps browsers and browser plug-ins current, removing known vulnerabilities that malicious or compromised websites could exploit for client execution. The safeguard does not prevent drive-by attacks relying on zero-day vulnerabilities, social engineering, or malicious browser notifications.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1190 Exploit Public-Facing Application
Comments
Automated application patching removes known vulnerabilities from externally exposed web applications, databases, VPN products, management platforms, and other application services. It does not correct insecure configurations, unsupported custom code, or vulnerabilities for which no vendor patch exists.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1203 Exploitation for Client Execution
Comments
Applying current security updates to browsers, Office products, PDF readers, and other client applications reduces successful exploitation of known application vulnerabilities. Operating-system vulnerabilities and unknown application vulnerabilities require separate protections.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1072 Software Deployment Tools
Comments
Patching centralized deployment and endpoint-management applications removes known vulnerabilities that could provide adversaries with privileged access or enterprise-wide remote execution. The safeguard does not prevent abuse through stolen administrator credentials or legitimate product functionality.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1137.003 Outlook Forms
Comments
Applying current Outlook security updates can disable or restrict custom forms that adversaries may abuse for persistence and execution. The safeguard does not prevent all malicious Office content or abuse of an unpatched or unsupported Outlook installation.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1137.004 Outlook Home Page
Comments
Outlook application updates remove or restrict the legacy Home Page feature used to load malicious content when a folder is accessed. The relationship depends on deploying the relevant Outlook security updates.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1137.005 Outlook Rules
Comments
Applying current Outlook patches reduces abuse of rule-triggered Visual Basic and related persistence mechanisms. It does not prevent all malicious mailbox-rule activity or activity performed through valid cloud-account access.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1555.003 Credentials from Web Browsers
Comments
Automated browser updates remove known vulnerabilities that could expose stored passwords, tokens, or browser authentication data. Patching does not prevent credential theft by malware already executing with sufficient access to the browser profile.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1555.005 Password Managers
Comments
Automated updates to password-manager applications remove known vulnerabilities that could expose stored or decrypted credentials.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1574.001 DLL
Comments
Applying vendor patches to vulnerable applications can correct unsafe DLL search paths, missing library references, and other side-loading conditions that allow an adversary-controlled DLL to execute. It does not prevent DLL hijacking in unpatched software or through writable application directories.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1068 Exploitation for Privilege Escalation
Comments
Application patching removes known vulnerabilities in privileged applications, agents, services, and third-party drivers that could allow escalation of privileges. Operating-system and kernel vulnerabilities are addressed separately through operating-system patch management.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1210 Exploitation of Remote Services
Comments
Application patching removes known vulnerabilities from third-party database, web, virtualization, file-transfer, remote-management, and similar services used for lateral movement. Vulnerabilities in operating-system-supplied remote services require operating-system patching.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1211 Exploitation for Stealth
Comments
Updating applications and security products can remove known vulnerabilities that adversaries could exploit to conceal activity or impair application-level visibility. Operating-system and kernel implementations are outside this safeguard's application scope.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1212 Exploitation for Credential Access
Comments
Application patching removes known vulnerabilities in authentication products, browsers, identity applications, network-management products, and other credential-handling software. Vulnerabilities in operating-system authentication components require operating-system patching.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1137 Office Application Startup
Comments
Application patches can restrict specific Outlook startup and persistence mechanisms, including Outlook Forms, Home Page, and Rules. Other Office startup mechanisms that rely on macros, add-ins, templates, or configuration changes are not necessarily prevented by patching.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1555 Credentials from Password Stores
Comments
Application patching can remove browser and password-manager vulnerabilities used to extract stored credentials. Operating-system credential stores and cloud secrets platforms may require different update mechanisms.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1574 Hijack Execution Flow
Comments
Application updates can correct unsafe DLL search paths and other software defects that permit DLL side-loading. Most other execution-flow hijacking implementations require permissions, application control, or operating-system configuration protections.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1176 Software Extensions
Comments
Updating browsers and IDEs can remove insecure extension mechanisms, but it does not prevent a user or adversary from installing an otherwise permitted malicious extension.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1176.001 Browser Extensions
Comments
Automated browser updates can remove deprecated extension-loading mechanisms and strengthen extension permission and installation controls. Extension allowlisting and trusted-source restrictions remain necessary to prevent malicious extensions.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1176.002 IDE Extensions
Comments
Updating IDE applications can correct vulnerabilities in extension loading and provide improved extension security controls. The safeguard does not independently prevent installation of a malicious or compromised extension from an approved marketplace.
References
CIS-7.4 Perform Automated Application Patch Management mitigates T1539 Steal Web Session Cookie
Comments
Updating browsers, password managers, and related applications reduces exploitation of known vulnerabilities used to extract session cookies. It does not prevent cookie theft by malware or an adversary that already has sufficient access to browser storage or memory.
References
CIS-7.3 Perform Automated Operating System Patch Management mitigates T1495 Firmware Corruption
Comments
Applying BIOS, UEFI, device, and component firmware updates can remove vulnerabilities that permit unauthorized firmware modification or corruption. Other protections are still required against adversaries that already possess authorized firmware-update capability.
References
CIS-7.3 Perform Automated Operating System Patch Management mitigates T1542 Pre-OS Boot
Comments
This is a partial parent mapping because remediation of vulnerable BIOS, UEFI, and component firmware can remove known pre-OS exploitation paths. Other pre-OS persistence methods may require boot-integrity, signing, and hardware-root-of-trust controls.
References
CIS-7.3 Perform Automated Operating System Patch Management mitigates T1542.001 System Firmware
Comments
Applying current BIOS and UEFI updates directly remediates known system-firmware vulnerabilities that could enable persistence or execution below the operating system.
References
CIS-7.3 Perform Automated Operating System Patch Management mitigates T1542.002 Component Firmware
Comments
Firmware updates for storage devices, controllers, network adapters, and other components remove known vulnerabilities that could allow malicious component-level persistence or modification.
References
CIS-7.3 Perform Automated Operating System Patch Management mitigates T1176.002 IDE Extensions
Comments
ATT&CK mentions ensuring operating systems and software are using the most current version.
References
    CIS-7.3 Perform Automated Operating System Patch Management mitigates T1176.001 Browser Extensions
    Comments
    ATT&CK mentions ensuring operating systems and software are using the most current version.
    References
      CIS-7.3 Perform Automated Operating System Patch Management mitigates T1176 Software Extensions
      Comments
      ATT&CK mentions ensuring operating systems and software are using the most current version.
      References
        CIS-7.3 Perform Automated Operating System Patch Management mitigates T1072 Software Deployment Tools
        Comments
        ATT&CK mentions having a patch deployment systems regularly to prevent potential remote access through Exploitation for Privilege Escalation.
        References
          CIS-7.3 Perform Automated Operating System Patch Management mitigates T1195.002 Compromise Software Supply Chain
          Comments
          ATT&CK mentions a patch management process should be implemented to check unused dependencies, unmaintained and/or previously vulnerable dependencies, unnecessary features, components, files, and documentation.
          References
            CIS-7.3 Perform Automated Operating System Patch Management mitigates T1195.001 Compromise Software Dependencies and Development Tools
            Comments
            ATT&CK mentions a patch management process should be implemented to check unused dependencies, unmaintained and/or previously vulnerable dependencies, unnecessary features, components, files, and documentation.
            References
              CIS-7.3 Perform Automated Operating System Patch Management mitigates T1195 Supply Chain Compromise
              Comments
              ATT&CK mentions a patch management process should be implemented to check unused dependencies, unmaintained and/or previously vulnerable dependencies, unnecessary features, components, files, and documentation.
              References
                CIS-7.3 Perform Automated Operating System Patch Management mitigates T1546 Event Triggered Execution
                Comments
                OS patches that address specific Windows event-triggered execution mechanisms, particularly Application Shimming.
                References
                  CIS-7.3 Perform Automated Operating System Patch Management mitigates T1552 Unsecured Credentials
                  Comments
                  ATT&CK specifically recommends applying patch KB2962486 which prevents credentials from being stored in GPPs.
                  References
                    CIS-7.3 Perform Automated Operating System Patch Management mitigates T1686.002 Network Device Firewall
                    Comments
                    ATT&CK specifically recommends maintaining network firewalls with current security patches. Include this where network firewall appliances and their operating systems are considered enterprise assets covered by the automated an OS-patching process.
                    References
                      CIS-7.3 Perform Automated Operating System Patch Management mitigates T1548 Abuse Elevation Control Mechanism
                      Comments
                      OS updates can close vulnerabilities and implementation weaknesses used to bypass native elevation mechanisms, especially UAC, but they do not prevent abuse of sudo permissions, temporary cloud elevation, or other correctly functioning mechanisms.
                      References
                        CIS-7.3 Perform Automated Operating System Patch Management mitigates T1211 Exploitation for Stealth
                        Comments
                        OS updates can correct vulnerabilities in kernels, logging components, security tools, and system services that could be exploited to conceal activity. Application-specific exploitation remains outside 7.3.
                        References
                          CIS-7.3 Perform Automated Operating System Patch Management mitigates T1210 Exploitation of Remote Services
                          Comments
                          OS patching directly addresses vulnerabilities in operating-system services such as SMB, RDP, RPC, SSH components, and other built-in remote services. The technique also includes independently installed applications that would fall under application patch management instead.
                          References
                            CIS-7.3 Perform Automated Operating System Patch Management mitigates T1550.002 Pass the Hash
                            Comments
                            ATT&CK identifies Windows 7 and higher system patch KB2871997 as limiting default access available to local administrator accounts, reducing some pass-the-hash lateral movement.
                            References
                              CIS-7.3 Perform Automated Operating System Patch Management mitigates T1552.006 Group Policy Preferences
                              Comments
                              ATT&CK identifies Windows patch KB2962486, which prevents credentials from being stored in Group Policy Preferences. This is a direct OS-patch implementation.
                              References
                                CIS-7.3 Perform Automated Operating System Patch Management mitigates T1546.011 Application Shimming
                                Comments
                                ATT&CK identifies a specific Windows patch, KB3045645, that removes an auto-elevation behavior used to abuse application shims. Automated OS patch deployment directly applies this type of mitigation.
                                References
                                  CIS-7.3 Perform Automated Operating System Patch Management mitigates T1548.002 Bypass User Account Control
                                  Comments
                                  Windows updates include changes that close known UAC-bypass methods and improve elevation protections. ATT&CK directly recommends maintaining the latest Windows version and patch level.
                                  References
                                    CIS-7.3 Perform Automated Operating System Patch Management mitigates T1611 Escape to Host
                                    Comments
                                    Container and VM escapes may exploit vulnerabilities in the host kernel, hypervisor, or operating-system components. ATT&CK explicitly recommends keeping hosts current with security patches.
                                    References
                                      CIS-7.3 Perform Automated Operating System Patch Management mitigates T1068 Exploitation for Privilege Escalation
                                      Comments
                                      OS and kernel vulnerabilities are a primary means of escalating from user privileges to SYSTEM or root. Automated OS patching directly removes known vulnerable code paths. ATT&CK specifically recommends patch management for internal endpoints and servers.
                                      References

                                        Capabilities

                                        Capability ID Capability Name Number of Mappings
                                        CIS-7.7 Remediate Detected Vulnerabilities 35
                                        CIS-7.4 Perform Automated Application Patch Management 21
                                        CIS-7.3 Perform Automated Operating System Patch Management 23