Critical vulnerabilities with Common Vulnerability Scoring System scores of 9.0 or higher pose severe risks to organisations' information systems. Timely detection and remediation are essential to minimise economic and reputational damage from cyberattacks. This paper provides a thorough analysis of the identification and resolution timelines of such critical vulnerabilities. A mixed-methods approach is employed, integrating quantitative data from global vulnerability databases analysing 245,456 Common Vulnerabilities and Exposures records spanning from 2009 to 2024, of which 12.8 % were critical, with qualitative case studies of notable incidents. This methodical combination of quantitative and qualitative data sources enables the identification of patterns and delay factors in vulnerability management. The findings indicate significant delays in public disclosure and patch deployment, influenced by industry-specific factors, resource availability and organisational processes. The paper concludes with a series of actionable recommendations to improve the efficiency of vulnerability responses. Despite faster disclosure, the remediation gap for critical vulnerabilities remains a systemic risk, driven by organisational inertia and system complexity.
翻译:通用漏洞评分系统(CVSS)评分达到9.0及以上的高危漏洞对组织的信息系统构成严重威胁。及时发现并修复此类漏洞对于最大限度降低网络攻击造成的经济和声誉损失至关重要。本文对这类高危漏洞的识别与修复时间线进行了深入分析。研究采用混合方法,整合来自全球漏洞数据库中245,456条通用漏洞披露(CVE)记录的定量数据(时间跨度为2009年至2024年,其中12.8%属于高危漏洞),并结合典型安全事件的定性案例研究。通过定量与定性数据源的系统性结合,本文揭示了漏洞管理中的模式特征与延迟因素。研究结果表明,受行业特性、资源可用性及组织流程的影响,漏洞公开披露与补丁部署存在显著延迟。本文最后提出了一系列可操作性建议,以提升漏洞响应效率。尽管披露速度有所提升,但受组织惯性与系统复杂性的影响,高危漏洞的修复缺口仍构成系统性风险。