CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium

A phishing campaign delivers a malicious Excel attachment. The vulnerability it exploits only triggers if the recipient opens the file and clicks 'Enable Content' to run the embedded macro. Which CVSS v3.1 base metric value best reflects this exploitation requirement?

  1. AUI:R (User Interaction: Required)
  2. BUI:N (User Interaction: None)
  3. CPR:H (Privileges Required: High)
  4. DAC:H (Attack Complexity: High)
Show answer & explanation

Correct answer: A. UI:R (User Interaction: Required)

The User Interaction (UI) metric captures whether a human other than the attacker must take an action, such as opening a file and enabling a macro, for the exploit to succeed; this scenario matches UI:R.

Why the other options are wrong

  • B. UI:N would apply only if no user action were needed, which contradicts the scenario.
  • C. PR:H concerns attacker privilege level on the target, not victim interaction.
  • D. AC:H concerns conditions outside the attacker's control (e.g., race conditions), not user clicks.

CVSS User Interaction (UI)

A CVSS Base metric indicating whether successful exploitation requires action by a user other than the attacker.

  • Values: None (N) or Required (R)
  • UI:R lowers severity relative to UI:N
  • Common in phishing/macro-based attacks

Memory trick: UI:R — the victim must Reach out and click.

More Vulnerability Management questions