T1499.004SubTechniqueimpactagent-callable

T1499.004Application or System Exploitation

Sub-technique of T1499

Platforms: Windows · Azure AD · Office 365 · SaaS · IaaS · Linux · macOS · Google Workspace

ATT&CK version: 14.1

What it is

Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users. (Citation: Sucuri BIND9 August 2015) Some systems may automatically restart critical applications and services when crashes occur, but they can likely be re-exploited to cause a persistent denial of service (DoS) condition. Adversaries may exploit known or zero-day vulnerabilities to crash applications and/or systems, which may also lead to dependent applications and/or systems to be in a DoS condition. Crashed or restarted applications or systems may also have other effects such as [Data Destruction](https://attack.mitre.org/techniques/T1485), [Firmware Corruption](https://attack.mitre.org/techniques/T1495), [Service Stop](https://attack.mitre.org/techniques/T1489) etc. which may further cause a DoS condition and deny availability to critical information, applications and/or systems.

ATT&CK tactics· 1

Impact

References

  1. https://attack.mitre.org/techniques/T1499/004
  2. https://blog.sucuri.net/2015/08/bind9-denial-of-service-exploit-in-the-wild.html
Sourced from MITRE ATT&CK Enterprise v14.1. Curated and contextualized for EU compliance use cases by Adam Lundqvist, Founder at SQUR.