In an ideal world, organizations would patch every new vulnerability once it’s discovered. In real-life, this is impossible. Security analysts responsible for vulnerability management activities face multiple challenges that result in what the industry calls “The Patching Paradox” – common sense tells you to keep every system up to date in order to be protected, but this is not possible due to limited resources, existence of legacy systems and slow implementation of patches.

Verint’s Cyber Threat Intelligence (CTI) Group analyzed the top 20 vulnerabilities that are currently exploited by attack groups worldwide. The goal of this analysis is to provide security professionals with an incentive to improve their patching management activities.


  • 34% of the attacks exploiting these vulnerabilities, originated in China
  • 45% of the vulnerabilities affect Microsoft products
  • Vulnerabilities from as early as 2012 (!) are still used to carry out successful attacks

According to the National Vulnerability Database (NVD), since 2016 we have seen an increase of ~130% in the number of disclosed vulnerabilities, or in other words there is an average of ~45 new vulnerabilities per day as can be seen in the graph below. Additional statistics reveal that almost 60% of all vulnerabilities are classified as ‘Critical’ or ‘High’.

Recent threat intelligence gathered by Verint and Thales Group about 66 attack groups operating globally, revealed that advanced threat actors leverage old vulnerabilities that are left unpatched. To make things even more complicated, according to a recent study by Ponemon Institute for ServiceNow60% of breaches were linked to a vulnerability where a patch was available, but not applied.


Operational Threat Intelligence – Each CVE is given a severity score. However, these scores do not necessarily represent the actual risk for the organization. For example, CVE-2018-20250 (WinRAR vulnerability) has a CVSS (Common Vulnerability Scoring System) base score of 7.8 (‘High’) in NVD and 6.8 (‘Medium’) in ‘CVE Details’. This vulnerability has been exploited by at least five different APT groups, from different locations, against targets in the U.S., South East Asia, Europe, and The Middle East and against a wide range of industries, including Government Agencies, Financial Services, Defense, Energy, Media and more. This information clearly indicates the criticality of the vulnerability and the urgency for immediate patching.

Other contextual data that should influence your patching prioritization process is what vulnerabilities are currently discussed in the Dark Web by threat actors, or which exploits are currently developed? Threat intelligence is key when we try to determine what vulnerabilities are critical to our organization. Maintaining a knowledge base of exploited vulnerabilities according to the attack groups leveraging them, provides a solid starting point for vulnerability prioritization. In addition, having information about the attack groups – for example their capabilities, TTPs and the industries and countries they target – helps to better evaluate the risk and prioritize patching activities.

The 20 vulnerabilities were extracted based on the number of times they have been exploited by sophisticated cyber-attack groups operating in the world today (from high to low):

No.CVEProducts Affected by CVECVSS Score (NVD)First-Last Seen (#Days)Examples of Threat Actors
1CVE-2017-11882Microsoft Office7.8713APT32 (Vietnam), APT34 (Iran), APT40 (China), APT-C-35 (India), Cobalt Group (Spain, Ukraine), Silent Group (Russia), Lotus Blossom (China), Cloud Atlas (Unknown), FIN7 (Russia)
2CVE-2018-8174Microsoft Windows7.5558Silent Group (Russia), Dark Hotel APT (North Korea)
3CVE-2017-0199Microsoft Office, Windows7.8960APT34 (Iran), APT40 (China), APT-C-35 (India), Cobalt Group (Spain, Ukraine), APT37 (North Korea), Silent Group (Russia), Gorgon Group (Pakistan), Gaza Cybergang (Iran)
4CVE-2018-4878Adobe Flash Player, Red Hat Enterprise Linux9.8637APT37 (North Korea), Lazarus Group (North Korea)
5CVE-2017-10271Oracle WebLogic Server7.5578Rocke Gang (Chinese Cybercrime)
6CVE-2019-0708Microsoft Windows9.8175Kelvin SecTeam (Venezuela, Colombia, Peru)
7CVE-2017-5638Apache Struts10864Lazarus Group (North Korea)
8CVE-2017-5715ARM, Intel5.6424Unknown
9CVE-2017-8759Microsoft .net Framework7.8671APT40 (China), Cobalt Group (Spain, Ukraine), APT10 (China)
10CVE-2018-20250RARLAB WinRAR7.8189APT32 (Vietnam), APT33 (Iran), APT-C-27 (Iran), Lazarus Group (North Korea), MuddyWater APT (Iran)
11CVE-2018-7600Debian, Drupal9.8557Kelvin SecTeam (Venezuela, Colombia, Peru), Sea Turtle (Iran)
12CVE-2018-10561DASAN Networks9.8385Kelvin SecTeam (Venezuela, Colombia, Peru)
13CVE-2017-17215Huawei8.8590‘Anarchy’ (Unknown)
14CVE-2012-0158MicrosoftN/A; 9.3 (according to (Russia), APT-C-35 (India), Cobalt Group (Spain, Ukraine), Lotus Blossom (China), Cloud Atlas (Unknown), Goblin Panda (China), Gorgon Group (Pakistan), APT40 (China)
15CVE-2014-8361D-Link, RealtekN/A; 10 (according to‘Anarchy’ (Unknown)
16CVE-2017-8570Microsoft Office7.8552APT-C-35 (India), Cobalt Group (Spain, Ukraine), APT23 (China)
17CVE-2018-0802Microsoft Office7.8574Cobalt Group (Spain, Ukraine), APT37 (North Korea), Silent Group (Russia), Cloud Atlas (Unknown), Cobalt Group (Spain, Ukraine), Goblin Panda (China), APT23 (China), APT27 (China), Rancor Group (China), Temp.Trident (China)
18CVE-2017-0143Microsoft SMB8.1959APT3 (China), Calypso (China)
19CVE-2018-12130Fedora5.6167Iron Tiger (China), APT3 (China), Calypso (China)
20CVE-2019-2725Oracle WebLogic Server9.8144Panda (China)
BONUSCVE-2019-3396Atlassian Confluence9.8204APT41 (China), Rocke Gang (Chinese Cybercrime)

For more, click here.