EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsMedium

A penetration tester is evaluating an organization's internal network security. During the reconnaissance phase, they discover several Windows systems running outdated software versions with known vulnerabilities. The tester then crafts a malicious executable that exploits one of these vulnerabilities, gaining remote code execution without any user interaction. This type of malware is specifically designed to take advantage of software flaws. Which term best describes this malicious executable?

  1. AExploit
  2. BBackdoor
  3. CMalware dropper
  4. DWorm
Show answer & explanation

Correct answer: A. Exploit

An exploit is a piece of software, data, or sequence of commands that takes advantage of a bug or vulnerability in a system to cause unintended or unanticipated behavior, often leading to control over the system. The scenario describes crafting an executable to 'exploit one of these vulnerabilities, gaining remote code execution'.

Why the other options are wrong

  • B. A backdoor is a hidden entry point, not necessarily the mechanism for initial compromise via a vulnerability.
  • C. A malware dropper is designed to install other malware, but the initial mechanism for compromise described is a vulnerability exploit.
  • D. A worm is self-replicating malware; while it might use exploits, the executable itself that targets the vulnerability is the exploit.

Exploit

A piece of code or sequence of commands that takes advantage of a software vulnerability to achieve an attacker's goal.

  • Targets specific vulnerabilities (e.g., buffer overflows, SQL injection).
  • Can lead to remote code execution, privilege escalation, or data theft.
  • Often a component of a larger attack chain.

Memory trick: Exploits use flaws to open doors.

More Malware Threats questions