risk
Exploitation of known, unpatched vulnerabilities
Use of software with publicly known, unpatched flaws (CVEs) that adversaries readily exploit — including recently discovered vulnerabilities exploited before mitigations are in place, and internal-system vulnerability exploitation.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Vulnerability & Patch Management
- Secure Configuration & Change Management
- taxonomy
- iso-27005-vulnerability
- nist-800-30-threat-event
- iso-27005-threat
- inherent_rating
- critical
Details
- risk_id
- vuln-unpatched-known-flaws
- category
- cyber_security
- likelihood
- high
- impact
- high
- inherent_rating
- critical
- treatment
- mitigate
- taxonomies
- iso-27005-vulnerability
- nist-800-30-threat-event
- iso-27005-threat
Source
No record-specific source URL is provided.
Connections
- UC-CONFIG-07 — Perform controlled, timely maintenance of systems and hardware mitigates Exploitation of known, unpatched vulnerabilities
- strength
- related
- rationale
- Timely maintenance and vendor support keep systems supportable and patchable, indirectly reducing unpatched-flaw exposure; patching is the operative control.
- UC-CONFIG-01 — Harden systems to approved secure configuration baselines mitigates Exploitation of known, unpatched vulnerabilities
- strength
- related
- rationale
- Least-functionality hardening disables vulnerable services and shrinks the exploitable surface, reducing exposure to known flaws; patching is the operative control.
- UC-VULN-05 — Block malware, spam, and phishing across all systems mitigates Exploitation of known, unpatched vulnerabilities
- strength
- related
- rationale
- Anti-malware and web filtering block exploit-kit malware that leverages known unpatched flaws, a compensating layer.
- UC-VULN-07 — Harden runtime error handling, output filtering, and memory mitigates Exploitation of known, unpatched vulnerabilities
- strength
- related
- rationale
- Memory-protection mitigations reduce exploit success for known memory-corruption flaws pending a patch.
- UC-VULN-04 — Test software security during development and acceptance mitigates Exploitation of known, unpatched vulnerabilities
- strength
- related
- rationale
- Development-stage analysis surfaces known-vulnerable components before they reach production.
- UC-VULN-02 — Test security through independent penetration exercises mitigates Exploitation of known, unpatched vulnerabilities
- strength
- related
- rationale
- Pen tests find and validate exploitable unpatched flaws and track corrective actions to verified closure.
- UC-CONFIG-04 — Build security and privacy into software design and upkeep mitigates Exploitation of known, unpatched vulnerabilities
- strength
- primary
- rationale
- Applying security patches within risk-based timeframes and replacing unsupported software directly mitigates exploitation of known unpatched flaws.
- UC-VULN-03 — Remediate identified flaws within defined timeframes mitigates Exploitation of known, unpatched vulnerabilities
- strength
- primary
- rationale
- Installing security updates within risk-based timeframes and verifying by rescan directly defends against exploitation of known unpatched flaws.
- UC-ASSET-09 — Receive, analyze, and act on threat and vulnerability intelligence mitigates Exploitation of known, unpatched vulnerabilities
- strength
- related
- rationale
- Vulnerability-disclosure/advisory intake surfaces known flaws and feeds remediation, but scanning and patching are the operative defenses against unpatched-CVE exploitation.
- UC-VULN-01 — Scan for vulnerabilities and track advisories on a defined cadence mitigates Exploitation of known, unpatched vulnerabilities
- strength
- primary
- rationale
- Scanning plus advisory subscription identifies known unpatched CVEs and tracks them to closure within severity-based timeframes.
- UC-BCDR-16 — Participate in cyber threat intelligence sharing mitigates Exploitation of known, unpatched vulnerabilities
- strength
- related
- rationale
- Shared alerts on actively-exploited known vulnerabilities drive prioritized remediation.