vulnerabilitycveexploitationrisk

VulnCheck - State of Exploitation: A Decade of Data

it underscores the escalating risk of vulnerability exploitation and provides empirical support for prioritizing known exploited vulnerabilities in supply chain decisions.

Summary

VulnCheck's analysis of vulnerability trends from 2014 to 2023 reveals a significant shift in threat actor tactics toward vulnerability exploitation, driven by the wider adoption of controls like MFA. According to referenced reports, exploitation initiated 38% of intrusions in 2023 and experienced a 180% increase in volume. The data shows that CVEs with known exploitation grew at a 19.7% annual rate, outpacing the 14.1% growth in overall CVE disclosures. Among all published vulnerabilities, 1.1% are known to be exploited in the wild, 2% are weaponized (possessing a payload-delivering exploit), and 31% have Proof-of-Concept (PoC) exploit code available. Notably, 72.9% of vulnerabilities exploited in the wild are associated with a PoC exploit, making PoC availability a critical indicator of exploitation risk. The report strongly advises prioritizing known exploitation and weaponized vulnerabilities for remediation.

Related Checks

VULN_ACTIVE_VERSION_KEV_EXPLOITED

The report finds that 1.1% of published vulnerabilities are exploited in the wild and explicitly recommends prioritizing known exploitation as an optimal starting point for addressing vulnerabilities.

Adverse Outcome

deploying software that is actively targeted and compromised by threat actors

Because

vulnerabilities with known exploitation have moved from theoretical risk to proven, real-world attacks.

Gaps Analysis

Evidence

The report states that 31% of vulnerabilities have Proof-of-Concept (PoC) exploit code, and 72.9% of vulnerabilities exploited in the wild are associated with a PoC exploit.

Blind Spot

Risk Guard checks for known exploitation via KEV catalogs but does not measure the availability of Proof-of-Concept exploit code, which the report identifies as a strong precursor to exploitation.

Actionable Capability

Risk Guard would be better if it flagged vulnerabilities with publicly available Proof-of-Concept exploits to anticipate exploitation before it is added to a KEV catalog.

Evidence

The analysis found that 2% of vulnerabilities are 'weaponized', defined as having an available exploit capable of delivering a significant payload.

Blind Spot

Risk Guard currently evaluates the presence of vulnerabilities and KEV status, but cannot distinguish vulnerabilities that have been weaponized with significant payloads from those that have not.

Actionable Capability

Risk Guard would be better if it integrated exploit weaponization intelligence to elevate the risk severity of vulnerabilities with payload-delivering exploits.

← Previous Next →