JELAJAH SOC
YO

Security operations

Vulnerability management

A findings list is not a work plan. Here you practise the ranking that matters: exploitability in the wild, asset criticality and exposure — then convert the top of the list into remediation the business can actually schedule.

Findings

12

Open critical

3

Exploited in the wild

7

Mean time to remediate

18 days

target: 7 days for critical

Findings

Sorted by composite risk, not severity label.

FindingSeverityCVSSExploit prob.AssetsRiskState

CVE-2024-31129

Remote code execution in report rendering library

critical9.871%2Open

CVE-2024-21762

Out-of-bounds write in VPN appliance handler

critical9.683%1Open

CVE-2024-25600

Unauthenticated code execution in CMS plugin

critical9.868%1Open

CVE-2024-20881

Privilege escalation via print spooler service

critical9.144%2Mitigating

CVE-2023-44487

Protocol stream multiplexing resource exhaustion

high7.562%1Mitigating

CVE-2024-1086

Use-after-free in kernel packet filter

high7.836%2Open

CVE-2023-38831

Archive handler executes hidden payload on open

high7.855%3Mitigating

CVE-2024-27983

HTTP/2 request-flood denial of service

high8.219%1Open

CVE-2023-4863

Heap overflow in image decoding component

medium6.529%2Resolved

CVE-2024-3094

Malicious code in compression library build chain

medium6.38%1Accepted risk

CVE-2024-26229

Local elevation via CSC service driver

medium5.95%2Open

CVE-2024-0519

Out-of-bounds memory access in browser engine

low3.72%1Resolved

CVE-2024-31129

Remote code execution in report rendering library

criticalOpenexploited in the wild
Package
report-render
Installed → fixed
3.2.13.2.6
First detected
6 days ago
Composite risk
100/100

Affected assets

  • SRV-WEB-01High
  • SRV-BUILD-03High

Remediation path: upgrade report-render to 3.2.6. If a maintenance window is weeks away, record a compensating control (network restriction, detection rule, monitoring uplift) rather than leaving the finding silently open.

Why severity alone produces the wrong work ordermethod

Two findings can both be CVSS 9.8 while one has a public exploit on an internet-facing crown-jewel asset and the other needs local access on a lab machine. Ranking by severity treats them identically and burns credibility with the teams who do the patching. The composite score used here multiplies base severity by exploitation likelihood and by asset criticality — the same three inputs every risk-based vulnerability programme uses, whatever the tooling.

Handing findings to owners without frictionpractice
  • Group by owning team and by fix action, not by CVE — one upgrade often closes several findings.
  • State the exact target version. “Patch it” creates a conversation; a version number creates a ticket.
  • Name the compensating control you will run until the fix lands, so risk acceptance is explicit and time-boxed.
  • Re-scan and close the loop; an unverified fix is a rumour.

Learn this capability

Labs covering risk prioritisation, technique vocabulary and response trade-offs.