FORENSIA

ATT&CK · T1203

Exploitation for Client Execution

Tactics: execution

About

Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility. Several types exist: ### Browser-based Exploitation Web browsers are a common target through Drive-by Compromise and Spearphishing Link. Endpoint systems may be compromised through normal web browsing or from certain users being targeted by links in spearphishing emails to adversary controlled sites used to exploit the web browser. These often do not require an action by the user for the exploit to be executed. ### Office Applications Common office and productivity applications such as Microsoft Office are also targeted through Phishing. Malicious files will be transmitted directly as attachments or through links to download them. These require the user to open the document or file for the exploit to run. ### Common Third-party Applications Other applications that are commonly seen or are part of the software deployed in a target network may also be used for exploitation. Applications such as Adobe Reader and Flash, which are common in enterprise environments, have been routinely targeted by adversaries attempting to gain access to systems. Depending on the software and nature of the vulnerability, some may be exploited in the browser or require the user to open a file. For instance, some Flash exploits have been delivered as objects within Microsoft Office documents.

Platforms: Linux, macOS, WindowsMITRE ATT&CK ↗

Corpus indicators tagged with this technique

346 indicators in the corpus carry T1203.

IndicatorTypeFamilySevSrc
cve-2017-17215cve852
cve-2018-8007cve851
cve-2024-1781cve851
b659389cde06f5e01e592dca458fe1be07a302c40dc2a820c7f76d4ee788bad3hashransomware802
6190923b28679eb8230010aff9b1d1a4184e8697540cc021a5be38126f3f6d99hashransomware802
72bed9b26a7747252156b65d24a9a737d70b9bf6aca069c514c1c7b9e04ef9b6hashransomware802
2528df60e55f210a6396dd7740d76afe30d5e9e8684a5b8a02a63bdcb5041bfchashransomware802
8bd16897409ae5d5667c345276d2532f493c0f98hashransomware802
42a99a5effdc1d02f6b622537de881e1hashransomware802
308351124c496d4f4effee65ab828506abf70385773c167ab1f32a7f030385achash802
3b6cb20891bce8602ce669187754871e402a1782031ef8b032cd007e3894bc5dhash802
442af2726e22f512b49f67bcdbf7c0d1e806aa8bhashransomware802
3e62797fd746ce9bd5d49cb833b7d9ac62d6b7a2hashransomware802
d78f64551d1b31a31e5998e442f0debd458e011e05019b3951d9ddde997f8384hash802
87480b151e465b73151220533c965f3a77046138f079ca3ceb961a7d5fee9a33hash801
b0e292346b4ab3f83fadd8abcce7cfc5b9d50ef73ad141e8bc4a4689fee13504hashransomware802
b371fbdce6935039218d4b4272db3521881c9cec48ef82dec1e9e0188a32d3adhash801
2b2e657ae1bc2fdcdfe5201a8e0e5224hashransomware802
f0b3e112ce4807a28e2b5d66a840ed7fhashransomware802
54a6743781fd4ceb720331fce92f16186931192dhashransomware802
edbf152ed9ac79e5d9e0111d1071af48hashransomware802
b0cfa2089802634ffb8c77962cdb18317a6332d4hashransomware802
64a0ab00d90682b1807c5d7da1a4ae67cde4c5757fc7d995d8f126f0ec8ae983hashransomware802
43f4ca1c7474c0476a42d937dc4af01c8ccfc20331baa0465ac0f3408f52b2e2hashransomware802
6a69ea2ce3fea0ebfd7a32a1dfc4251bd4d7d8a4fbd44aaa47b82290d0414a9fhash802
7890b116d13a52efe696ce1e2c0ed83029775cf4bea836ce551e71d222ee116fhashransomware802
f962e15c6efebb3c29fe399bb168066042b616affddd83f72570c979184ec55chashransomware802
6c700ca4e6d917c7aa9d964e98604a0349d9b8b4673df96a3f73a3d2d042635ahash802
28a9982cf2b4fc53a1545b6ed0d0c1788ca9369a847750f5652ffa0ca7f7b7d3hashransomware802
259fd28f9e66159d5a30b86688fec184hashransomware802

Showing the top 30 by severity of 346.