Ep46: Vulnerability Prioritization: Why 98.5% of CVEs Are Never Exploited
Roughly 98.5% of all known CVEs have never been exploited. In this episode I break down a conversation between Jeremiah Grossman and Robert Hansen of Root Evidence, and host Raphael Mudge, on the Down the Rabbit Hole podcast, and what it means for how you prioritize a patch queue. I cover CVSS score versus exploitation evidence, how to use CISA's free KEV catalog, why the vulnerability management industry has no incentive to tell you the truth, and what separates a junior-sounding answer from a senior one in a security interview.
In this episode:
- (00:00) The scan report that isn't as urgent as it looks
- (01:03) The 98.5% number and the mechanic analogy
- (02:01) Why the industry defaulted to patch everything
- (03:00) The 36-hour outage from a perfect-10 patch
- (03:48) CVSS score vs. exploitation evidence vs. insurance-claims data
- (05:08) What it sounds like when someone understands this in an interview
- (06:15) Why the industry has no brakes, and the AI-hype myth
- (07:49) Your homework
Links:
- Down the Rabbit Hole, episode 722, "Vulnerability Math Ain't Mathing"
- CISA's Known Exploited Vulnerabilities (KEV) catalog
- FIRST.org, the CVSS specification
- Full written breakdown
- Our cybersecurity career guide
- Breaking into cybersecurity with no experience
- Third-party risk and the AI bug-report flood
Not financial or legal advice. Figures cited reflect Root Evidence's analysis as discussed on the source podcast episode.
I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode.
--
Find subscriber links on my site, add to your podcast player, or listen on the web players on my site:
--
Support this Podcast with a Tip:
--
If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast.
Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity
