Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Error’d: Pickup Sticklers

      September 27, 2025

      From Prompt To Partner: Designing Your Custom AI Assistant

      September 27, 2025

      Microsoft unveils reimagined Marketplace for cloud solutions, AI apps, and more

      September 27, 2025

      Design Dialects: Breaking the Rules, Not the System

      September 27, 2025

      Building personal apps with open source and AI

      September 12, 2025

      What Can We Actually Do With corner-shape?

      September 12, 2025

      Craft, Clarity, and Care: The Story and Work of Mengchu Yao

      September 12, 2025

      Cailabs secures €57M to accelerate growth and industrial scale-up

      September 12, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Using phpinfo() to Debug Common and Not-so-Common PHP Errors and Warnings

      September 28, 2025
      Recent

      Using phpinfo() to Debug Common and Not-so-Common PHP Errors and Warnings

      September 28, 2025

      Mastering PHP File Uploads: A Guide to php.ini Settings and Code Examples

      September 28, 2025

      The first browser with JavaScript landed 30 years ago

      September 27, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured
      Recent
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»CISA, NIST Researchers Develop Metric to Determine Likelihood of Vulnerability Exploitation

    CISA, NIST Researchers Develop Metric to Determine Likelihood of Vulnerability Exploitation

    May 20, 2025

    vulnerability exploit exploitation likelihood

    Researchers from the U.S. National Institute of Standards and Technology (NIST) and the Cybersecurity and Infrastructure Security Agency (CISA) have developed a new security metric to determine the likelihood that a vulnerability has been exploited.

    In a paper published this week, Peter Mell, formerly of NIST, and CISA’s Jonathan Spring outlined their vulnerability exploit metric that augments the work of the Exploit Prediction Scoring System (EPSS) and CISA’s Known Exploited Vulnerabilities (KEV) catalog.

    Mell and Spring cited studies that have found that only 5% of vulnerabilities have been observed to be exploited in the wild, while the monthly vulnerability remediation rate for companies is 16%.

    “The remediation rate is so low because it is expensive for companies to address vulnerabilities,” they wrote. “…This situation would not be a problem if the 16% were to cover the 5%, but metrology is lacking to accurately make that calculation. Thus, predicting which vulnerabilities will be exploited is critically important for the efficiency and cost-effectiveness of enterprise vulnerability remediation efforts.”

    Vulnerability Exploit Metric Builds on EPSS

    Mell and Spring noted known shortcomings in EPSS and the CISA KEV catalog.

    EPSS “has known inaccurate values,” they wrote, while KEV is likely not comprehensive. Their proposed likelihood metric could help augment EPSS remediation by correcting some inaccuracies, and could build on the KEV catalog by “enabling measurements of comprehensiveness.”

    EPSS provides probabilities that a vulnerability will be observed to be exploited in the wild within the next 30 days, the NIST and CISA researchers said. “However, its probabilities are known to be inaccurate for vulnerabilities that have been previously observed to be exploited,” they wrote. “… Fortunately, the probabilities are not randomly inaccurate; they underestimate the true probability.”

    Mell and Spring call their formula Likely Exploited Vulnerabilities (LEV) probabilities. LEV probabilities have at least four use cases, they said. These include:

    1. Measuring the expected number and proportion of vulnerabilities that actors have exploited
    2. Estimating the comprehensiveness of the KEV catalog
    3. Augmenting KEV-based vulnerability remediation prioritization by “identifying higher probability vulnerabilities that may be missing”
    4. Augmenting EPSS-based vulnerability remediation prioritization by “identifying vulnerabilities that may be underscored.”

    Results: Hundreds of Vulnerabilities with High Probability of Exploitation

    The paper listed two vulnerabilities where LEV and EPSS probabilities differed.

    For CVE-2023-1730, a SQL injection vulnerability in the SupportCandy WordPress plugin before 3.1.5, the LEV probability was 0.70, while the peak EPSS score was 0.16.

    For CVE-2023-29373, a Microsoft ODBC Driver Remote Code Execution vulnerability, the LEV probability was 0.54350, while the peak EPSS probability was 0.08.

    Their work also identified several hundred vulnerabilities with a probability approaching 1.0.

    “Interestingly, many of these vulnerabilities are not included in tested KEV lists,” Mell and Spring wrote. “… This is one reason that LEV lists cannot replace KEV lists. LEV cannot identify which of the many low probability vulnerabilities will be exploited, it can only help compute how many of them are expected to be exploited. KEV lists identify the exact ones that have been exploited.”

    Mell and Spring said they’re looking for industry partners to collaborate with to obtain performance measurements of the LEV metric.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleInnovating with MongoDB | Customer Successes, May 2025
    Next Article Hazy Hawk Exploits DNS Records to Hijack CDC, Corporate Domains for Malware Delivery

    Related Posts

    Development

    Using phpinfo() to Debug Common and Not-so-Common PHP Errors and Warnings

    September 28, 2025
    Development

    Mastering PHP File Uploads: A Guide to php.ini Settings and Code Examples

    September 28, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    Eliminating Manual Cheque Errors Why UAE Businesses Need Cheque Printing Software

    Web Development

    Google Pixel 10 Adds C2PA Support to Verify AI-Generated Media Authenticity

    Development

    Microsite Architecture in Optimizely Spire

    Development

    Free Ad Text Generator

    Web Development

    Highlights

    Chinese Student Jailed for Smishing: Operated Covert “SMS Blaster” in Car for Mass Phishing

    July 1, 2025

    Chinese Student Jailed for Smishing: Operated Covert “SMS Blaster” in Car for Mass Phishing

    A Chinese student has been sentenced to over a year in prison by Inner London Crown Court for orchestrating a mobile SMS-based phishing (smishing) campaign using a covert “SMS Blaster” system hidden i …
    Read more

    Published Date:
    Jul 02, 2025 (1 hour, 23 minutes ago)

    Vulnerabilities has been mentioned in this article.

    How to Protect Your GitHub Repos Against Malicious Clones

    July 16, 2025

    Send Notifications in Laravel with Firebase Cloud Messaging and Notifire

    August 5, 2025

    Farmonics Pizza Seasoning – Authentic Italian Blend for Perfect Pizza, Pasta & More

    June 20, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.