{
  "node_id": "mitre-attack-t1203-exploitation-for-client-execution",
  "title": "MITRE ATT&CK T1203: Exploitation for Client Execution (Enterprise Tactic TA0002 - Execution)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE ATT&CK T1203 (Exploitation for Client Execution) is an Enterprise Execution technique. Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Affected platforms: Linux, Windows, macOS. MITRE-documented mitigations include M1050 Exploit Protection, M1051 Update Software, M1048 Application Isolation and Sandboxing. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-04, AC-06, CA-07, CM-08, SC-02, SC-03, SC-07, SC-18.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-framework-v14"
  ],
  "primary_citations_count": 7
}