Note: This article covers version 1 of the EPSS score. A version 4 has since been released with significant improvements. To learn more, check out our updated article on EPSS v4.
While the CVSS (Common Vulnerability Scoring System) is widely used to assess the severity of IT vulnerabilities, new methods regularly emerge to offer a different perspective on the same problem. This article covers a score called EPSS, or "Exploit Prediction Scoring System," which indicates the probability that a vulnerability will be exploited.
EPSS: A method created in 2019 to highlight vulnerabilities that are both severe and actively exploited
The EPSS (Exploit Prediction Scoring System) score was created in 2019 during a presentation at Black Hat (a famous cybersecurity conference).
This project, initiated by researchers Jay Jacobs, Sasha Romanosky, Benjamin Edwards, Michael Roytman, and Idris Adjerid, aims to provide a solution to a common question in vulnerability management: how to prioritize vulnerabilities present in an information system?
What problem does the Exploit Prediction Scoring System aim to solve?
In their Black Hat presentation, the creators of EPSS highlight several market observations, namely:
- Too many vulnerabilities are published compared to the number of vulnerabilities that security teams can actually address;
- Less than 5% of vulnerabilities are actually exploited by attackers.
They specifically highlight the findings of a 2013 presentation by Luca Allodi and Fabio Massacci, which indicate that:
- Fixing high or medium-level vulnerabilities that have automated attack kits improves security levels by 62.81%;
- Fixing high or medium-level vulnerabilities that have attack kit demonstrations improves security levels by 19.64%;
- Fixing high or medium-level vulnerabilities improves security levels by 3.2%.
What solution does the Exploit Prediction Scoring System offer?
The creators of the EPSS score propose calculating the probability that each vulnerability will actually be exploited in a cyberattack within 12 months.
This probability is calculated based on the characteristics of each vulnerability and a prediction model that relies on 16 variables, including: the presence of a readily usable exploit kit, the vendor of the affected product (Microsoft, Adobe, HP, Apache, IBM, Apple, Google), the type of vulnerability (memory corruption, code execution, denial of service), the possibility of remote or local exploitation, and the number of references associated with the vulnerability.
Using these characteristics and a model trained on all CVEs published in the MITRE database, a mathematical formula (log-odds) is used to calculate the probability of exploitation for each vulnerability.
Note that these characteristics can change over time. For example, the types of exploits available for a CVE can change based on hacker interest. This means the EPSS score can evolve over time. The EPSS score is therefore a dynamic score, whereas the CVSSv3.1 score is generally used as a static score (which is not entirely true, since the CVSSv3.1 score includes a "temporal" criterion that can change over time, but this criterion is rarely used in the market except by tools like Cyberwatch Vulnerability Manager).
Case study: calculating the Exploit Prediction Scoring System for CVE-2019-0708
The article introducing EPSS provides an example using CVE-2019-0708 (BlueKeep).
CVE-2019-0708 (BlueKeep) has a CVSSv3.1 score of 9.8/10 and an EPSS score of 95.2%.
The Exploit Prediction Scoring System makes it possible to calculate the probability of a vulnerability being exploited and highlights the vulnerabilities most likely to be used in the wild.
The main benefit of the EPSS score is that the range of values generated can be very wide between two CVEs. Visually, it is therefore quite easy to distinguish vulnerabilities that require immediate attention.
Using a sample of vulnerabilities linked to a demonstration IT environment, we can plot the distribution of CVEs based on their base CVSSv3.1 score and their EPSS score.
The distribution of vulnerabilities based on their EPSS score immediately reveals a trend, whereas an analysis limited to the base CVSSv3.1 score fails to highlight specific vulnerabilities.
The EPSS score provides a result similar to a full implementation of the CVSSv3.1 standard using the Exploit Code Maturity temporal criterion.
Comparison of an EPSS score approach versus a CVSSv3.1 score with Exploit Code Maturity
Since the EPSS score provides information regarding the exploitability of a vulnerability, it essentially provides information similar to the full use of the CVSSv3.1 standard when taking into account the temporal criterion, particularly the "Exploit Code Maturity" criterion.
This criterion, denoted as "E" in the CVSSv3.1 standard, indicates the maturity level of exploit kits available for a vulnerability. Vulnerabilities with an Exploit Code Maturity level of "High" are the most dangerous because it indicates that the exploit kit is very easy to use.
An Exploit Code Maturity level of "Functional" indicates that the kit is available but requires some effort from the attacker. Meanwhile, a value of "Proof-of-Concept" indicates that the kit is available but only works if the attacker puts in significant effort to adapt the code to their target.
Finally, a value of "Unproven" indicates that no exploit kit is currently known.
When taking this criterion into account and analyzing the vulnerabilities of a standard IT infrastructure, it becomes clear that filtering for vulnerabilities with a critical base score (CVSSv3.1 base score of 9 or higher out of 10) and a High Exploit Code Maturity also provides a highly relevant analysis of the priority actions to be taken within the infrastructure.
This approach shows that 2.32% of vulnerabilities have both a critical CVSSv3.1 score and a High Exploit Code Maturity.
Detailed analysis of the differences in results between EPSS and CVSSv3.1 with Exploit Code Maturity
Let's now compare the results of the two approaches CVE by CVE, by selecting the top 10 from each method on a demonstration set representative of market information systems.
We observe that:
- Some CVEs appear in both lists, such as CVE-2022-22965 (Spring4Shell), CVE-2021-44228 (Log4Shell), CVE-2019-11043 (vulnerability in PHP FPM), CVE-2020-0796 (SMBGhost), CVE-2019-2725 (vulnerability in Oracle WebLogic), and CVE-2019-0708 (BlueKeep);
- The approach based solely on CVSSv3.1 criteria highlights CVE-2020-1472 (Zerologon), CVE-2018-17456 (vulnerability in Git), CVE-2021-31166 (vulnerability in Microsoft Windows HTTP.sys), and CVE-2020-9850 (vulnerability in Apple products, notably Safari);
- The approach based on the EPSS score additionally identifies CVE-2021-40438 (vulnerability in the Apache HTTP Server mod_proxy component), CVE-2017-8464 (vulnerability in Microsoft Windows), CVE-2017-0144 (an EternalBlue series vulnerability in Microsoft Windows), and CVE-2017-0037 (vulnerability in Microsoft Windows Internet Explorer and Edge).
In both cases, some notable vulnerabilities are not included: the "Top 10 critical CVSSv3.1 with High Exploit Code Maturity" method fails to capture CVE-2017-0144 (part of the EternalBlue series), while the "Top 10 EPSS scores" method does not include CVE-2020-1472 (Zerologon).
No method is perfect, and the two approaches are actually complementary.
What are the advantages and disadvantages of the Exploit Prediction Scoring System?
The EPSS score is available faster than the NVD CVSS score and therefore provides an initial level of analysis for a recent CVE: EPSS advantage
The NVD CVSS score relies on the assessment capabilities of NIST teams. In practice, the CVSS score is sometimes provided by the NVD only several days after a CVE is published.
Conversely, the EPSS score is calculated using the formulas mentioned earlier in this article. Consequently, the EPSS score is provided very quickly and offers an initial overview of the importance of a new vulnerability.
A prime example of this situation is CVE-2022-20477, published on December 13, 2022. As of 1:00 PM (Paris time) on December 14, 2022, the NVD had not yet provided a CVSS score, yet it already had an EPSS score of 11.9%.
The EPSS score highlights significant trends within an information system: EPSS advantage
The EPSS score varies significantly from one CVE to another, helping to identify trends within an information system by distributing CVEs with the highest EPSS scores across a given IT infrastructure.
The Exploit Prediction Scoring System highlights vulnerabilities from specific manufacturers, unlike the more neutral CVSS: CVSS advantage
By design, the EPSS calculation formula emphasizes vulnerabilities related to products from Microsoft, IBM, Adobe, HP, Apache, Google, and Apple.
Consequently, when a vulnerability involves technology outside of these manufacturers, it will typically have a relatively low EPSS score.
This is the case with CVE-2022-42475, which concerns FortiOS; it is actively exploited and highly dangerous despite having a low EPSS score.
The Exploit Prediction Scoring System is currently less well-known and recognized than the CVSS score: CVSS advantage
The EPSS score is recent and remains a work in progress. This method has not yet reached a consensus, particularly due to the lack of neutrality of its creators.
Jonathan Spring, a member of the CERT/CC, notes in his article "Probably Don't Rely on EPSS Yet" that the model was trained using data from AlienVault or Fortinet sensors, which introduces bias. He also points out that vulnerabilities listed as actively exploited in the CISA KEV (Known Exploited Vulnerabilities) database have very low EPSS scores when they involve the Internet of Things.
Conversely, the CVSS score is widely used by most IT security auditors and the vast majority of vulnerability management software in the industry.
In conclusion, EPSS and CVSS are complementary methods, and one cannot replace the other.
A comprehensive analysis shows that the EPSS score is not a magic formula that can replace CVSS, but rather a complementary method for analyzing information system vulnerabilities that can be useful in specific situations.
When a particularly recent vulnerability has not yet been evaluated by the NVD and lacks a CVSS score, EPSS is highly useful for gaining insight into the potential danger of the CVE.
Similarly, it can be relevant to analyze assets based on the maximum EPSS score detected on them to identify trends within the information system.
However, a well-utilized CVSSv3.1 score, incorporating temporal and even environmental criteria, is equally effective for prioritizing risks using a rational approach recognized by the entire market.
Furthermore, analysts wishing to use methods complementary to the CVSS score may look into the MITRE ATT&CK framework, which analyzes the combined effects of multiple CVEs—a method now widely recognized by the market.
Finally, while CVSSv3.1 is subject to regular criticism, it is important to remember that these critiques exclusively concern the base CVSSv3.1 score; when the full CVSSv3.1 standard is used, including temporal and environmental scores, the majority of these flaws disappear.
How do you get the Exploit Prediction Scoring System for your vulnerabilities?
Cyberwatch Vulnerability Manager includes a vulnerability encyclopedia with all available EPSS scores and makes it easy to generate reports focused on this metric.
Feel free to reach out to us via our contact form to request a demo.
