T1190 Exploit Public-Facing Application — ATT&CK Technique
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets. On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers. Depending on the flaw being exploited, this may also involve Exploitation for Stealth or Exploitation for Client Execution. If an application is hosted on cloud-based infrastructure and/or is containerized, then exploiting it may lead to compromise of the underlying instance or container. This can allow an adversary a path to access the cloud or container APIs (e.g., via the Cloud Instance Metadata API), exploit container host access via Escape to Host, or take advantage of weak identity and access management policies. Adversaries may also exploit edge network infrastructure and related appliances, specifically targeting devices that do not support robust host-based defenses. For websites and databases, the OWASP top 10 and CWE top 25 highlight the most common web-based vulnerabilities.
Detection coverage (50)
- CVE-2010-5278 Exploitation Attempt critical
- Rejetto HTTP File Server RCE high
- Pulse Secure Attack CVE-2019-11510 critical
- Fortinet CVE-2018-13379 Exploitation critical
- Oracle WebLogic Exploit critical
- Confluence Exploitation CVE-2019-3398 critical
- Exploited CVE-2020-10189 Zoho ManageEngine high
- Cisco ASA FTD Exploit CVE-2020-3452 high
- Citrix Netscaler Attack CVE-2019-19781 critical
- CVE-2020-10148 SolarWinds Orion API Auth Bypass critical
- CVE-2020-0688 Exploitation via Eventlog high
- TerraMaster TOS CVE-2020-28188 high
- CVE-2020-0688 Exchange Exploitation via Web Log critical
- Oracle WebLogic Exploit CVE-2020-14882 high
- CVE-2020-0688 Exploitation Attempt high
- Citrix ADS Exploitation CVE-2020-8193 CVE-2020-8195 critical
- Exploitation of CVE-2021-26814 in Wazuh high
- DNS RCE CVE-2020-1350 critical
- CVE-2020-5902 F5 BIG-IP Exploitation Attempt critical
- CVE-2021-21978 Exploitation Attempt high
- Fortinet CVE-2021-22123 Exploitation critical
- CVE-2021-21972 VSphere Exploitation high
- VMware vCenter Server File Upload CVE-2021-22005 high
- Oracle WebLogic Exploit CVE-2021-2109 critical
- Potential CVE-2021-26084 Exploitation Attempt high
- Potential CVE-2021-27905 Exploitation Attempt medium
- Arcadyan Router Exploitations critical
- Pulse Connect Secure RCE Attack CVE-2021-22893 high
- Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt high
- Exchange Exploitation CVE-2021-28480 critical
- OMIGOD SCX RunAsProvider ExecuteScript high
- CVE-2021-33766 Exchange ProxyToken Exploitation critical
- OMIGOD HTTP No Authentication RCE - CVE-2021-38647 high
- ProxyLogon Reset Virtual Directories Based On IIS Log critical
- ADSelfService Exploitation high
- CVE-2021-40539 Zoho ManageEngine ADSelfService Plus Exploit critical
- LPE InstallerFileTakeOver PoC CVE-2021-41379 high
- CVE-2021-41773 Exploitation Attempt high
- Sitecore Pre-Auth RCE CVE-2021-42237 high
- Grafana Path Traversal Exploitation CVE-2021-43798 critical
- SonicWall SSL/VPN Jarrewrite Exploitation high
- Exchange Exploitation Used by HAFNIUM high
- Potential CVE-2021-44228 Exploitation Attempt - VMware Horizon high
- Log4j RCE CVE-2021-44228 Generic high
- Log4j RCE CVE-2021-44228 in Fields high
- Exchange ProxyShell Pattern high
- Potential CVE-2022-21587 Exploitation Attempt high
- Potential CVE-2022-26809 Exploitation Attempt high
- CVE-2022-31656 VMware Workspace ONE Access Auth Bypass high
- Zimbra Collaboration Suite Email Server Unauthenticated RCE medium
Malware using this technique
Threat actors using this technique
- Medusa Ransomware
- Rocke
- APT27
- FIN7
- Volt Typhoon
- Void Manticore
- Sandworm Team
- APT28
- Kimsuky
- Ember Bear
- BackdoorDiplomacy
- GOLD SOUTHFIELD
- FIN13
- BlackTech
- APT35
- Medusa Group
- Sea Turtle
- Storm-0501
- Fox Kitten
- Cinnamon Tempest
- BlackByte
- APT15
- Agrius
- APT10
- ToddyCat
- Blue Mockingbird
- GALLIUM
- Winter Vivern
- Earth Lusca
- APT29
- APT40
- Volatile Cedar
- INC Ransom
- UNC3886
- MirrorFace
- Moses Staff
- Dragonfly
- Axiom
- APT41
- Play Ransomware
- HAFNIUM
- APT5
- MuddyWater
- Salt Typhoon
- APT39