Rants of a deranged squirrel.

A Glimpse Into the CISA KEV

On March 27, Elizabeth Cardona and Tod Beardsley gave a presentation at VulnCon 2024 about CISA’s KEV, or ‘Known Exploited Vulnerabilities’ list. This initiative was created as a result of BOD 22-01, which is a ‘Binding Operational Directive’ aimed at reducing the risk due to vulnerabilities that are known to be exploited in the wild, and that may impact federal, executive branch, departments and agencies. Many private organizations and companies also follow it closely as a guide to know what may be the biggest digital threat they face.

While the idea of the KEV is simple on the surface, Cardona and Beardsley gave us insight that shows it is not as straight-forward as it may seem. This blog aims to capture some of what they shared with a little commentary thrown in.


First, what criteria must be present for a vulnerability to be included in the KEV? Note that any quotes are direct from the speaker, but I did not note which speaker said it.

These are fairly easy to understand and they make sense, but there are some caveats and details that matter. First, the reliable evidence of exploitation means that there is the execution of malicious code, performed by an actor on a system without permission of the system owner, or attempted exploitation with the same criteria where the result would have been malicious code execution. In short, “bad guys doing bad things to another computer“. The criteria for this is quite high because it represents money federal agencies must spend in remediation efforts. A false positive on the KEV can waste thousands of hours and considerable money.

The speakers made a point to say the KEV is not there to predict exploitation, rather, it is evidence-based. Exploitation could happen against one system or a thousand, and that does not matter to them, as either can land a vulnerability on the list. CISA also does not care if the exploitation information comes from a federal agency, researcher, commercial company, or vendor. Beardsley also qualified that “if something is ripping across the Internet, you can read it elsewhere… the fact it is on the KEV or not is immaterial“. I believe this was speaking to cases where there was heavy news on active exploitation of a vulnerability while it not appearing on the KEV yet.

So, what does not count for inclusion in the KEV?

Next, what counts as ‘evidence’ in CISA’s eyes?

From here, the talk turned into a fairly extensive Q&A session. I’ll include some interesting bits from that before ending with future plans for the KEV. My comments in brackets for the following.

What does the future hold for KEV? The speakers briefly mentioned several things they hope to see in the future including:

Hopefully this sheds some light on the KEV. The talk was certainly interesting to me and helped me better understand the process and caveats for the initiative.

Before this talk, I certainly had some criticism of the KEV, but this talk really opened my eyes to some of the details on how they operate and why the KEV seemingly fell short. I think after the talk and thinking on it more, the big thing that stands out to me is the KEV is one thing while the industry thinks it is another thing. This talk bridged that gap for me. Now, my criticism is leveled more at organizations and vendors that have evidence of exploitation and don’t share it with CISA, so that the KEV can be updated more rapidly, and be more thorough.

Exit mobile version