Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Adversaries may abuse CMSTP to proxy execution of malicious code.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-03 | ✗→✓ | ▲ Improved | 37% | 0% |
| case-10 | ✗→✓ | ▲ Improved | 85% | 0% |
| case-11 | ✗→✓ | ▲ Improved | -25% | 0% |
| case-16 | ✗→✓ | ▲ Improved | 5% | 0% |
| case-19 | ✗→✓ | ▲ Improved | 19% | 0% |
> Sub-technique of: T1218
Adversaries may abuse CMSTP to proxy execution of malicious code. The Microsoft Connection Manager Profile Installer (CMSTP.exe) is a command-line program used to install Connection Manager service profiles. CMSTP.exe accepts an installation information file (INF) as a parameter and installs a service profile leveraged for remote access connections.
Adversaries may supply CMSTP.exe with INF files infected with malicious commands. Similar to Regsvr32 / ”Squiblydoo”, CMSTP.exe may be abused to load and execute DLLs and/or COM scriptlets (SCT) from remote servers. This execution may also bypass AppLocker and other application control defenses since CMSTP.exe is a legitimate binary that may be signed by Microsoft.
CMSTP.exe can also be abused to Bypass User Account Control and execute arbitrary commands from a malicious INF through an auto-elevated COM interface.
Platforms: Windows
The following tests are from Atomic Red Team and provide actionable ways to test this technique:
Adversaries may supply CMSTP.exe with INF files infected with malicious commands
Supported Platforms: windows
cmdcmstp.exe /s "#{inf_file_path}"
Dependencies:
Adversaries may invoke cmd.exe (or other malicious commands) by embedding them in the RunPreSetupCommandsSection of an INF file
Supported Platforms: windows
cmdcmstp.exe /s "#{inf_file_uac}" /au
Dependencies:
If Atomic Red Team tests are not applicable, manually verify the technique by:
Consider using application control configured to block execution of CMSTP.exe if it is not required for a given system or network to prevent potential misuse by adversaries.
CMSTP.exe may not be necessary within a given environment (unless using it for VPN connection installation).
| Finding | Severity | Impact | | -------------------------- | -------- | --------------- | | CMSTP technique applicable | Medium | Defense Evasion |
| CWE ID | Title | | ------- | ---------------------------- | | CWE-693 | Protection Mechanism Failure |
Other measured skills in the registry, with their headline benchmark lift.