CVE-2022-26925
published 2022-05-10CVE-2022-26925: Windows LSA Spoofing Vulnerability Windows LSA Spoofing Vulnerability
medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-07-22
Exploited in the wild
EPSS
10.46%
95.2th percentile
Windows LSA Spoofing Vulnerability
Windows LSA Spoofing Vulnerability
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | >= 0 < 5.4.0-187.207 | 5.4.0-187.207 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19297 | 10.0.10240.19297 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5125 | 10.0.14393.5125 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.2928 | 10.0.17763.2928 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.2928 | 10.0.17763.2928 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.2274 | 10.0.18363.2274 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1706 | 10.0.19042.1706 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1706 | 10.0.19043.1706 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19043.1706 | 10.0.19043.1706 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.675 | 10.0.22000.675 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.25954 | 6.1.7601.25954 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.25954 | 6.1.7601.25954 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20371 | 6.3.9600.20371 |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.25954 | 6.1.7601.25954 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.21481 | 6.0.6003.21481 |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.23714 | 6.2.9200.23714 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20371 | 6.3.9600.20371 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5125 | 10.0.14393.5125 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.2928 | 10.0.17763.2928 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.707 | 10.0.20348.707 |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < 10.0.19042.1706 | 10.0.19042.1706 |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_1909 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect anonymous connection attempts on the LSARPC interface — the exploit coerces domain controller authentication via an unauthenticated LSARPC method call ↗
- →Alert on NTLM authentication requests originating from domain controllers toward unexpected/attacker-controlled hosts — indicates active NTLM relay exploitation chained with CVE-2022-26925 ↗
- →Monitor for machine-in-the-middle (MITM) positioning on the logical network path between domain controllers and requested resources, as required by the attack's high-complexity precondition ↗
- →Prioritize detection on domain controllers: CVE-2022-26925 exploitation has been confirmed in the wild on both latest and older software releases ↗
- →Correlate CVE-2022-26925 NTLM coercion activity with NTLM Relay Attacks targeting Active Directory Certificate Services (AD CS) — chaining raises combined CVSSv3 to 9.8 and can lead to RCE ↗
- ·Applying the May 2022 patch to domain controllers without additional configuration changes breaks PIV/CAC (smart card) authentication — follow CISA implementation guidance before deploying to DCs ↗
- ·The EFS API OpenEncryptedFileRaw(A/W) used in backup software stops working on Windows Server 2008 SP2 after patching; all other Windows versions retain local and remote EFS backup functionality ↗
- ·Domain controllers must be patched on a priority basis before other servers due to the elevated risk of NTLM relay leading to remote code execution ↗
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
cvelistv58.1HIGH
osv6.5MEDIUM
vulncheck8.1HIGH
cisa5.9MEDIUM
vendor_msrc8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft Windows LSA Spoofing Vulnerability
cisa·2022-07-01·CVSS 5.9
CVE-2022-26925 [MEDIUM] CWE-306 Microsoft Windows LSA Spoofing Vulnerability
Vulnerability: Microsoft Windows LSA Spoofing Vulnerability
Affected: Microsoft Windows
Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM.
Required Action: Apply remediation actions outlined in CISA guidance [https://www.cisa.gov/guidance-applying-june-microsoft-patch].
Notes: WARNING: This update is required on all Microsoft Windows endpoints but if deployed to domain controllers without additional configuration changes the update breaks PIV/CAC authentication. Read CISA implementation guidance carefully before deploying to domain controllers.; https://nvd.nist.gov/vuln/detail/CVE-2022-26925
Remediation Due Date: 2022-07-22
Microsoft
Windows LSA Spoofing Vulnerability
vendor_msrc·2022-05-10·CVSS 8.1
CVE-2022-26925 [HIGH] Windows LSA Spoofing Vulnerability
Windows LSA Spoofing Vulnerability
FAQ: How could an attacker exploit this vulnerability?
An unauthenticated attacker could call a method on the LSARPC interface and coerce the domain controller to authenticate to the attacker using NTLM. This security update detects anonymous connection attempts in LSARPC and disallows it.
Is there more information available on how to protect my system?
Yes. Please see ADV210003 Mitigating NTLM Relay Attacks on Active Directory Certificate Services (AD CS).
Are there further actions I need to take to protect my system after I have applied the security update?
Yes. Please see KB5005413 for more information on the steps that you need to take to protect your system. Please note that the combined CVSS score would be 9.8 when this vulnerability is chained wit
OSV
linux-aws-5.4 vulnerabilities
osv·2024-07-10·CVSS 6.5
CVE-2022-0001 linux-aws-5.4 vulnerabilities
linux-aws-5.4 vulnerabilities
Sander Wiebing, Alvise de Faveri Tron, Herbert Bos, and Cristiano Giuffrida
discovered that the Linux kernel mitigations for the initial Branch History
Injection vulnerability (CVE-2022-0001) were insufficient for Intel
processors. A local attacker could potentially use this to expose sensitive
information. (CVE-2024-2201)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Netfilter;
(CVE-2024-26925, CVE-2024-26643)
OSV
linux, linux-aws, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, lin
osv·2024-07-03·CVSS 6.5
CVE-2022-0001 linux, linux-aws, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, lin
linux, linux-aws, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4, linux-xilinx-zynqmp vulnerabilities
Sander Wiebing, Alvise de Faveri Tron, Herbert Bos, and Cristiano Giuffrida
discovered that the Linux kernel mitigations for the initial Branch History
Injection vulnerability (CVE-2022-0001) were insufficient for Intel
processors. A local attacker could potentially use this to expose sensitive
information. (CVE-2024-2201)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Netfilter;
(CVE-2024-26925, CVE-2024-2664
Project0
2022 0-day In-the-Wild Exploitation…so far - Project Zero
project_zero·2022-06-01·CVSS 8.8
CVE-2016-5128 [HIGH] 2022 0-day In-the-Wild Exploitation…so far - Project Zero
Posted by Maddie Stone, Google Project Zero
This blog post is an overview of a talk, “ 0-day In-the-Wild Exploitation in 2022…so far”, that I gave at the FIRST conference in June 2022. The slides are available here.
For the last three years, we’ve published annual year-in-review reports of 0-days found exploited in the wild. The most recent of these reports is the 2021 Year in Review report, which we published just a few months ago in April. While we plan to stick with that annual cadence, we’re publishing a little bonus report today looking at the in-the-wild 0-days detected and disclosed in the first half of 2022.
As of June 15, 2022, there have been 18 0-days detected and disclosed as exploited in-the-wild in 2022. When we analyzed those 0-days, we found that at least nin
CVEList
Windows LSA Spoofing Vulnerability
cvelistv5·2022-05-10·CVSS 8.1
CVE-2022-26925 [HIGH] Windows LSA Spoofing Vulnerability
Windows LSA Spoofing Vulnerability
Windows LSA Spoofing Vulnerability
VulnCheck
Microsoft Windows LSA Spoofing Vulnerability
vulncheck·2022·CVSS 8.1
CVE-2022-26925 [HIGH] CWE-306 Microsoft Windows LSA Spoofing Vulnerability
Microsoft Windows LSA Spoofing Vulnerability
Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM.
Affected: Microsoft Windows
Required Action: Apply remediation actions outlined in CISA guidance [https://www.cisa.gov/guidance-applying-june-microsoft-patch].
Known Ransomware Campaign Use: Known
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2022-May; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://securelist.com/it-threat-evolution-in-q2-2022-non-mobile-statistics/107133/; https://raw.githubusercontent.com/
No detection rules found.
No public exploits indexed.
Securelist
IT threat evolution in Q2 2022. Non-mobile statistics
blogs_securelist·2022-08-15
IT threat evolution in Q2 2022. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Ransomware programs
Quarterly trends and highlights
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used by criminals during cyberattacks
Quarterly highlights
Vulnerability statistics
Attacks on macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks via web resources
TOP 10 countries and territories that serve as sources of web-based attacks
Countries and territories where users faced the greatest risk of online infection
Local threat
Securelist
Non-mobile malware statistics, Q2 2022
blogs_securelist·2022-08-15
Non-mobile malware statistics, Q2 2022
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by criminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q2 2022
- IT threat evolution in Q2 2022. Non-mobile statistics
- IT threat evolution in Q2 2022. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q2 2022:
- Kaspersky solutions blocked 1,164,544,060 attacks from online resources across the globe.
- Web Anti-Virus recognized 273,033,368 unique URLs as malicious. Attempts to run malware fo
Securelist
IT threat evolution Q2 2022
blogs_securelist·2022-08-15
IT threat evolution Q2 2022
Table of Contents
- Targeted attacks
- Other malware
Authors
- David Emm
- IT threat evolution in Q2 2022
- IT threat evolution in Q2 2022. Non-mobile statistics
- IT threat evolution in Q2 2022. Mobile statistics
## Targeted attacks
### New technique for installing fileless malware
Earlier this year, we discovered a malicious campaign that employed a new technique for installing fileless malware on target machines by injecting a shellcode directly into Windows event logs. The attackers were using this to hide a last-stage Trojan in the file system.
The attack starts by driving targets to a legitimate website and tricking them into downloading a compressed RAR file that is booby-trapped with the network penetration testing tools Cobalt Strike and SilentBreak. The attackers use thes
Securelist
IT threat evolution Q2 2022
blogs_securelist·2022-08-15
IT threat evolution Q2 2022
Table of Contents
Targeted attacks
New technique for installing fileless malware
WinDealer’s man-on-the-side spyware
ToddyCat: previously unknown threat actor attacks high-profile organizations in Europe and Asia
SessionManager IIS backdoor
Other malware
Spring4Shell
Actively exploited vulnerability in Windows
Follina vulnerability in MSDT
BlackCat: a new ransomware gang
Yanluowang ransomware: how to recover encrypted files
Ransomware TTPs
Ransomware trends in 2022
Emotet’s return
Mobile subscription Trojans
The threat from stalkerware
Authors
David Emm
IT threat evolution in Q2 2022
IT threat evolution in Q2 2022. Non-mobile statistics
IT threat evolution in Q2 2022. Mobile statistics
## Targeted attacks
## New technique for installing fileless malware
Earlier this
Unit42
Threat Brief: Microsoft Critical Vulnerabilities (CVE-2022-26809, CVE-2022-26923, CVE-2022-26925)
blogs_unit42·2022-07-27·CVSS 9.8
CVE-2022-26809 [CRITICAL] Threat Brief: Microsoft Critical Vulnerabilities (CVE-2022-26809, CVE-2022-26923, CVE-2022-26925)
Threat Research Center
High Profile Threats
Vulnerabilities
## Threat Brief: Microsoft Critical Vulnerabilities (CVE-2022-26809, CVE-2022-26923, CVE-2022-26925)
Chao Lei
Tao Yan
Haozhe Zhang
Qi Deng
Published: July 27, 2022
High Profile Threats
Vulnerabilities
CVE-2022-26809
CVE-2022-26923
CVE-2022-26925
Microsoft
Microsoft Windows
## Executive Summary
Microsoft introduced patches for several critical vulnerabilities in their April and May 2022 security updates, including the following vulnerabilities:
CVE-2022-26809 : An unauthorized attacker can exploit this vulnerability by sending a specially crafted Remote Procedure Call (RPC) to remotely execute arbitrary code on the vulnerable device.
CVE-2022-26923 : A low-privileged user can escalate privilege to a domain ad
Unit42
Threat Brief: Microsoft Critical Vulnerabilities (CVE-2022-26809, CVE-2022-26923, CVE-2022-26925)
blogs_unit42·2022-07-27·CVSS 9.8
CVE-2022-26925 [CRITICAL] Threat Brief: Microsoft Critical Vulnerabilities (CVE-2022-26809, CVE-2022-26923, CVE-2022-26925)
## Executive Summary
Microsoft introduced patches for several critical vulnerabilities in their April and May 2022 security updates, including the following vulnerabilities:
- CVE-2022-26809: An unauthorized attacker can exploit this vulnerability by sending a specially crafted Remote Procedure Call (RPC) to remotely execute arbitrary code on the vulnerable device.
- CVE-2022-26923: A low-privileged user can escalate privilege to a domain administrator in a default Active Directory environment with the “Active Directory Certificate Services” server role installed.
- CVE-2022-26925: Unauthenticated attackers can remotely exploit and force domain controllers to authenticate them via the Windows NT LAN Manager (NTLM) security protocol.
We highly recommend that customers apply these securit
Krebs
Microsoft Patch Tuesday, May 2022 Edition
blogs_krebs·2022-05-11·CVSS 7.5
CVE-2022-26925 [HIGH] Microsoft Patch Tuesday, May 2022 Edition
Microsoft today released updates to fix at least 74 separate security problems in its Windows operating systems and related software. This month’s patch batch includes fixes for seven “critical” flaws, as well as a zero-day vulnerability that affects all supported versions of Windows.
By all accounts, the most urgent bug Microsoft addressed this month is CVE-2022-26925 , a weakness in a central component of Windows security (the “ Local Security Authority ” process within Windows). CVE-2022-26925 was publicly disclosed prior to today, and Microsoft says it is now actively being exploited in the wild. The flaw affects Windows 7 through 10 and Windows Server 2008 through 2022.
Greg Wiseman , product manager for Rapid7 , said Microsoft has rated this vulnerability as important and assigned
Krebs
Microsoft Patch Tuesday, May 2022 Edition
blogs_krebs·2022-05-11·CVSS 7.5
CVE-2022-26925 [HIGH] Microsoft Patch Tuesday, May 2022 Edition
Microsoft today released updates to fix at least 74 separate security problems in its Windows operating systems and related software. This month’s patch batch includes fixes for seven “critical” flaws, as well as a zero-day vulnerability that affects all supported versions of Windows.
By all accounts, the most urgent bug Microsoft addressed this month is CVE-2022-26925, a weakness in a central component of Windows security (the “Local Security Authority” process within Windows). CVE-2022-26925 was publicly disclosed prior to today, and Microsoft says it is now actively being exploited in the wild. The flaw affects Windows 7 through 10 and Windows Server 2008 through 2022.
Greg Wiseman, product manager for Rapid7, said Microsoft has rated this vulnerability as important and assigned it a
Tenable
Microsoft’s May 2022 Patch Tuesday Addresses 73 CVEs (CVE-2022-26925)
blogs_tenable·2022-05-10·CVSS 8.1
[HIGH] Microsoft’s May 2022 Patch Tuesday Addresses 73 CVEs (CVE-2022-26925)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
May 2022 Patch Tuesday | Microsoft Releases 75 Vulnerabilities With 8 Critical; Adobe Releases 5 Advisories, 18 Vulnerabilities With 16 Critical.
blogs_qualys·2022-05-10·CVSS 5.6
[MEDIUM] May 2022 Patch Tuesday | Microsoft Releases 75 Vulnerabilities With 8 Critical; Adobe Releases 5 Advisories, 18 Vulnerabilities With 16 Critical.
## Table of Contents
Microsoft Patch Tuesday Summary
Notable Microsoft Vulnerabilities Patched
Microsoft Last But Not Least
Notable Adobe Vulnerabilities Patched
About Qualys Patch Tuesday
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
Rapid Response with Patch Management (PM)
Qualys Monthly Webinar Series
Join the webinar this Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Summary
Microsoft has fixed 75 vulnerabilities in the May 2022 update, including one advisory ( ADV220001 ) for Azure in response to CVE-2022-29972 , a publicly exposed Zero-Day Remote Code Execution (RCE) Vulnerability, and eight vulnerabilities classified as critical as they allow Remote Code Execution (RCE) or Elevation of Privileges. This month
Qualys
May 2022 Patch Tuesday | Microsoft Releases 75 Vulnerabilities With 8 Critical; Adobe Releases 5 Advisories, 18 Vulnerabilities With 16 Critical. | Qualys
blogs_qualys·2022-05-10·CVSS 5.6
[MEDIUM] May 2022 Patch Tuesday | Microsoft Releases 75 Vulnerabilities With 8 Critical; Adobe Releases 5 Advisories, 18 Vulnerabilities With 16 Critical. | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- Notable Microsoft Vulnerabilities Patched
- Microsoft Last But Not Least
- Notable Adobe Vulnerabilities Patched
- About Qualys Patch Tuesday
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
- Rapid Response with Patch Management (PM)
- Qualys Monthly Webinar Series
- Join the webinar this Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Summary
Microsoft has fixed 75 vulnerabilities in the May 2022 update, including one advisory ( ADV220001 ) for Azure in response to CVE-2022-29972, a publicly exposed Zero-Day Remote Code Execution (RCE) Vulnerability, and eight vulnerabilities classified as critical as they allow Remote Code Execution (RCE) or Elevation of Privileges.
Crowdstrike
May 2022 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] May 2022 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
arXiv
Vulnerability Management Chaining: An Integrated Framework for Efficient Cybersecurity Risk Prioritization
arxiv_fulltext·2025-07-10
Vulnerability Management Chaining: An Integrated Framework for Efficient Cybersecurity Risk Prioritization
## Abstract
As the number of Common Vulnerabilities and Exposures (CVE) continues to grow exponentially, security teams face increasingly difficult decisions about prioritization. Current approaches using Common Vulnerability Scoring System (CVSS) scores produce overwhelming volumes of high-priority vulnerabilities, while Exploit Prediction Scoring System (EPSS) and Known Exploited Vulnerabilities (KEV) catalog offer valuable but incomplete perspectives on actual exploitation risk. We present Vulnerability Management Chaining, a decision tree framework that systematically integrates these three approaches to achieve efficient vulnerability prioritization. Our framework employs a two-stage evaluation process: first applying threat-based filtering using KEV membership or EPSS threshold 0.08
2022-05-10
Published
2022-07-01
Added to CISA KEV
Exploited in the wild