Coverage › CVE-2024-42009
CVE-2024-42009 Mapped Sigma
RoundCube Webmail Cross-Site Scripting Vulnerability
- Vendor / product
- Roundcube — Webmail
- Description (CISA)
- RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
- Added to KEV
- 2025-06-09
- Due date
- 2025-06-30
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known ransomware use
- Unknown
- CWE
- CWE-79
- CISA notes
- https://roundcube.net/news/2024/08/04/security-updates-1.6.8-and-1.5.8
https://nvd.nist.gov/vuln/detail/CVE-2024-42009 - Elsewhere
- cve.org · NVD · CISA KEV · JSON
ATT&CK techniques · CTID Mappings Explorer, ATT&CK 16.1, KEV snapshot 2025-07-28
3 mapping objects across 3 techniques. exploitation technique states how the vulnerability is exploited; primary and secondary impact state what exploitation achieves. They are different claims and are labelled as such.
| Technique | Mapping type | CTID comment | Status in v19.2 |
|---|---|---|---|
| T1566.002 Spearphishing Link | exploitation technique | An attacker can exploit a deserialization/desanitization issue by injecting malicious JavaScript into a message. Parsing the HTML inside the message can allow the exfiltration of email data, as well as commandeer the victim's browser. ref 1 |
live |
| T1056 Input Capture | primary impact | An attacker can exploit a deserialization/desanitization issue by injecting malicious JavaScript into a message. Parsing the HTML inside the message can allow the exfiltration of email data, as well as commandeer the victim's browser. ref 1 |
live |
| T1114 Email Collection | primary impact | An attacker can exploit a deserialization/desanitization issue by injecting malicious JavaScript into a message. Parsing the HTML inside the message can allow the exfiltration of email data, as well as commandeer the victim's browser. ref 1 |
live |
Detection chain · ATT&CK Enterprise v19.2 detection strategies, analytics, log sources
T1056 Input Capture primary impact
- DET0102 Behavioral Detection of Input Capture Across Platforms
AN0282 WindowsMonitors for abnormal process behavior and API calls like SetWindowsHookEx, GetAsyncKeyState, or device input polling commonly used for keystroke logging.Tunable:
TargetImageTimeWindowAN0283 LinuxDetects use of tools/scripts accessing input devices like /dev/input/* or evdev via suspicious processes lacking GUI context.Tunable:ProcessNameDevicePathAN0284 macOSMonitors for TCC-bypassing or unauthorized access to input services like IOHIDSystem or Quartz Event Services used in keylogging or screen monitoring.Tunable:ServiceParentProcessAN0285 Network DevicesDetects web-based credential phishing by analyzing traffic to suspicious URLs that mimic login portals and POST credential content.Tunable:UserAgentURL_Path
Sigma rules tagged attack.t1056 (2)
Author: Josh Nickels
· 2024-02-26 · logsource: product=windows category=dns_query · df68f791-ad95-447f-a271-640a0dab9cf8
Detects DNS query requests to "update.onelaunch.com". This domain is associated with the OneLaunch adware application.
When the OneLaunch application is installed it will attempt to get updates from this domain.
Author: Gavin Knapp
· 2023-03-16 · logsource: category=proxy · eb6c2004-1cef-427f-8885-9042974e5eb6
Detects connections to interplanetary file system (IPFS) containing a user's email address which mirrors behaviours observed in recent phishing campaigns leveraging IPFS to host credential harvesting webpages.
T1114 Email Collection primary impact
- DET0476 Email Collection via Local Email Access and Auto-Forwarding Behavior
AN1309 WindowsCorrelates creation of email forwarding rules or header anomalies (e.g., X-MS-Exchange-Organization-AutoForwarded) with suspicious process execution, file access of .pst/.ost files, and network connections to external SMTP servers.Tunable:
TimeWindowUserContextSMTPDomainListAN1310 LinuxDetects file access to mbox/maildir files in conjunction with curl/wget/postfix execution, or anomalous shell scripts harvesting user mail directories.Tunable:WatchedMailDirsProcessNameListTimeWindowAN1311 macOSMonitors Mail.app database or maildir file access, automation via AppleScript, and abnormal mail rule creation using scripting or UI automation frameworks.Tunable:ScriptProcessNameListWatchedMailFilesAN1312 Office SuiteCorrelates unusual auto-forwarding rule creation via Exchange Web Services or Outlook rules engine, presence of X-MS-Exchange-Organization-AutoForwarded headers, and logon session anomalies from abnormal IPs.Tunable:UserAgentListExternalSMTPDomainListTimeWindow
Sigma rules tagged attack.t1114 (4)
Author: Sorina Ionescu
· 2022-02-08 (modified 2022-11-17) · logsource: product=m365 service=threat_management · 18b88d08-d73e-4f21-bc25-4b9892a4fdd0
Alert on when a user has performed an eDiscovery search or exported a PST file from the search. This PST file usually has sensitive information including email body content
Author: Florian Roth (Nextron Systems)
· 2017-05-31 (modified 2022-10-09) · logsource: product=windows service=security · 24549159-ac1b-479c-8175-d42aea947cae
This events that are generated when using the hacktool Ruler by Sensepost
Author: FPT.EagleEye, Nasreddine Bencherchali (Nextron Systems)
· 2021-03-03 (modified 2023-03-24) · logsource: product=windows category=process_creation · 25676e10-2121-446e-80a4-71ff8506af47
Detects adding and using Exchange PowerShell snap-ins to export mailbox data. As seen used by HAFNIUM and APT27
Author: Nikita Khalimonenkov
· 2022-11-17 · logsource: product=m365 service=threat_management · 6897cd82-6664-11ed-9022-0242ac120002
Alert when a user has performed an export to a search using 'New-ComplianceSearchAction' with the '-Export' flag. This detection will detect PST export even if the 'eDiscovery search or exported' alert is disabled in the O365.This rule will apply to ExchangePowerShell usage and from the cloud.
T1566.002 Spearphishing Link exploitation technique
- DET0107 Detection Strategy for Spearphishing Links
AN0298 WindowsCorrelation of inbound emails with embedded links followed by user-driven browser navigation to suspicious or obfuscated domains. Detection chain includes malicious URL in email → user click recorded in Office logs → browser process spawning unusual child processes (e.g., PowerShell, cmd) or download activity.m365:unified
Send/Receive: Inbound emails containing embedded or shortened URLs→ DC0038 Application Log ContentTunable:SuspiciousTLDsURLShortenerDomainsClickToExecutionWindowAN0299 LinuxDetection of spearphishing links through mail logs and browser activity. Behavior includes email with suspicious URLs → user click recorded in mail/web proxy logs → shell or interpreter launched from browser process.Application:MailInbound emails containing hyperlinks from suspicious sources→ DC0038 Application Log Contentauditd:SYSCALLexecve: Execution of scripts or binaries spawned from browser processes→ DC0032 Process CreationNSM:FlowOutbound requests to domains not previously resolved or associated with phishing campaigns→ DC0078 Network Traffic FlowTunable:MonitoredBrowsersPhishingIndicatorsAN0300 macOSCorrelation of Mail.app logs with Safari/Chrome activity. Suspicious behavior includes email links → Safari/Chrome accessing newly registered or lookalike domains → osascript or Terminal spawned unexpectedly.macos:unifiedlogBrowser processes launching unexpected interpreters (osascript, bash)→ DC0032 Process Creationmacos:unifiedlogConnections to suspicious domains with mismatched certificate or unusual patterns→ DC0085 Network Traffic ContentTunable:CertificateAnomaliesExecutionDelayThresholdAN0301 Identity ProviderDetection of OAuth consent phishing or malicious login attempts initiated through spearphishing links. Behavior chain includes inbound email with OAuth URL → consent page visited → unusual token grants logged in IdP logs.azure:signinlogsConsentGrant: Suspicious consent grants to non-approved or unknown applications→ DC0038 Application Log ContentTunable:AllowedAppsAnomalousConsentPatterns
Sigma rules tagged attack.t1566.002 (4)
Author: Marco Pedrinazzi (@pedrinazziM) (InTheCyber)
· 2026-01-27 · logsource: product=m365 service=audit · 3569aefd-e535-4391-8c18-24bd01a21eaf
Detects instances where an email, identified as malicious or suspicious by the Microsoft Defender for Office 365 (formerly ATP) engine, was delivered to a user's Inbox or Junk folder.
It might indicate that a potential threat, such as a spearphishing attachment or links, has bypassed initial blocking mechanisms and reached an end-user, requiring further investigation and potential remediation.
Author: jamesc-grafana
· 2024-07-11 (modified 2025-12-08) · logsource: product=aws service=cloudtrail · 38e7f511-3f74-41d4-836e-f57dfa18eead
Detect when System Manager successfully executes commands against an instance.
Author: Tim Rauch (rule), Elastic (idea)
· 2022-10-21 (modified 2022-12-28) · logsource: product=macos category=process_creation · 6e4dcdd1-e48b-42f7-b2d8-3b413fc58cb4
Detects when the macOS Script Editor utility spawns an unusual child process.
Author: uniqu3-us3r
· 2026-04-28 · logsource: category=proxy · e0e121d0-be4d-4281-af7e-17abbba4a408
Detects outbound web proxy requests to URLs matching the EvilTokens Phishing-as-a-Service (PhaaS) kit infrastructure.
Specifically Cloudflare Workers and Railway.app domains used in OAuth device code authorization phishing attacks.
This indicates a user has clicked a phishing link.