Technique.View on attack.mitre.org
Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.
Several types exist:
### Browser-based Exploitation
Web browsers are a common target through Drive-by Compromise and Spearphishing Link. Endpoint systems may be compromised through normal web browsing or from certain users being targeted by links in spearphishing emails to adversary controlled sites used to exploit the web browser. These often do not require an action by the user for the exploit to be executed.
### Office Applications
Common office and productivity applications such as Microsoft Office are also targeted through Phishing. Malicious files will be transmitted directly as attachments or through links to download them. These require the user to open the document or file for the exploit to run.
### Common Third-party Applications
Other applications that are commonly seen or are part of the software deployed in a target network may also be used for exploitation. Applications such as Adobe Reader and Flash, which are common in enterprise environments, have been routinely targeted by adversaries attempting to gain access to systems. Depending on the software and nature of the vulnerability, some may be exploited in the browser or require the user to open a file. For instance, some Flash exploits have been delivered as objects within Microsoft Office documents.
Rules on DetectionCode tagged with T1203.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Cisco Secure Firewall - Binary File Type Download | Anomaly | NULL | Cisco Secure Firewall Threat Defense File Event |
| Cisco Secure Firewall - Blocked Connection | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event |
| Cisco Secure Firewall - Citrix NetScaler Memory Overread Attempt | TTP | NULL | Cisco Secure Firewall Threat Defense Intrusion Event |
| Cisco Secure Firewall - High Priority Intrusion Classification | TTP | NULL | Cisco Secure Firewall Threat Defense Intrusion Event |
| Cisco Secure Firewall - Malware File Downloaded | Anomaly | NULL | Cisco Secure Firewall Threat Defense File Event |
| Cisco Secure Firewall - Possibly Compromised Host | Anomaly | NULL | Cisco Secure Firewall Threat Defense Intrusion Event |
| Cisco Secure Firewall - Repeated Blocked Connections | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event |
| Detect Windows DNS SIGRed via Splunk Stream | TTP | NULL | |
| Detect Windows DNS SIGRed via Zeek | TTP | NULL | |
| Sunburst Correlation DLL and Network Event | TTP | NULL | Sysmon EventID 7, Sysmon EventID 22 |
| Windows MSC EvilTwin Directory Path Manipulation | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Remote Image Load | Anomaly | NULL | Sysmon EventID 7 |
| Used by | Procedure example |
|---|---|
| Groupadmin@338 | admin@338 has exploited client software vulnerabilities for execution, such as Microsoft Word CVE-2012-0158. |
| GroupAndariel | Andariel has exploited numerous ActiveX vulnerabilities, including zero-days. |
| GroupAoqin Dragon | Aoqin Dragon has exploited CVE-2012-0158 and CVE-2010-3333 for execution against targeted systems. |
| GroupAPT12 | APT12 has exploited multiple vulnerabilities for execution, including Microsoft Office vulnerabilities (CVE-2009-3129, CVE-2012-0158) and vulnerabilities in Adobe Reader and Flash (CVE-2009-4324, CVE-2009-0927, CVE-2011-0609, CVE-2011-0611). |
| GroupAPT28 | APT28 has exploited Microsoft Office vulnerability CVE-2017-0262 for execution. |
| GroupAPT29 | APT29 has used multiple software exploits for common client software, like Microsoft Word, Exchange, and Adobe Reader, to gain code execution. |
| GroupAPT3 | APT3 has exploited the Adobe Flash Player vulnerability CVE-2015-3113 and Internet Explorer vulnerability CVE-2014-1776. |
| GroupAPT32 | APT32 has used RTF document that includes an exploit to execute malicious code. (CVE-2017-11882) |
| Used by | Procedure example |
|---|---|
| MalwareAgent Tesla | Agent Tesla has exploited Office vulnerabilities such as CVE-2017-11882 and CVE-2017-8570 for execution during delivery. |
| MalwareBankshot | Bankshot leverages a known zero-day vulnerability in Adobe Flash to execute the implant into the victims’ machines. |
| MalwareCobalt Strike | Cobalt Strike can exploit Oracle Java vulnerabilities for execution, including CVE-2011-3544, CVE-2013-2465, CVE-2012-4681, and CVE-2013-2460. |
| MalwareDealersChoice | DealersChoice leverages vulnerable versions of Flash to perform execution. |
| MalwareEvilBunny | EvilBunny has exploited CVE-2011-4369, a vulnerability in the PRC component in Adobe Reader. |
| MalwareHAWKBALL | HAWKBALL has exploited Microsoft Office vulnerabilities CVE-2017-11882 and CVE-2018-0802 to deliver the payload. |
| MalwareInvisiMole | InvisiMole has installed legitimate but vulnerable Total Video Player software and wdigest.dll library drivers on compromised hosts to exploit stack overflow and input validation vulnerabilities for code execution. |
| MalwareRamsay | Ramsay has been embedded in documents exploiting CVE-2017-0199, CVE-2017-11882, and CVE-2017-8570. |
| Used by | Procedure example |
|---|---|
| Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus leveraged the Chrome vulnerability, CVE-2022-0609, in combination with a Drive-by Compromise website. |
| CampaignFrankenstein | During Frankenstein, the threat actors exploited CVE-2017-11882 to execute code on the victim's machine. |
| CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors exploited Adobe Flash vulnerability CVE-2011-0611, Microsoft Windows Help vulnerability CVE-2010-1885, and several Internet Explorer vulnerabilities, including CVE-2011-1255, CVE-2012-1889, and CVE-2014-0322. |
| CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda used the GrimResource exploitation technique via specially crafted MSC files for arbitrary code execution during RedDelta Modified PlugX Infection Chain Operations. |
| CampaignRedPenguin | During RedPenguin, UNC3886 exploited CVE-2025-21590 to bypass Veriexec protections in Junos OS designed to prevent unauthorized binary execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.