A company policy mandates that all critical vulnerabilities must be remediated within 7 days of discovery. A recent vulnerability scan identified a critical vulnerability (CVSS 9.0) in a legacy application that the vendor no longer supports, meaning no official patch is available. What is the MOST appropriate immediate action for the security team to take?
- ADisable the legacy application immediately.
- BDocument the risk acceptance for the unsupported application.
- CImplement a compensating control, such as network segmentation or an IPS rule.
- DDevelop a custom patch for the legacy application.
Show answer & explanationAnswer & explanation
Correct answer: C. Implement a compensating control, such as network segmentation or an IPS rule.
Simply documenting risk acceptance (A) without any mitigation is inappropriate for a critical vulnerability, especially when policy mandates remediation. Developing a custom patch (C) is often complex, costly, and beyond the immediate capabilities of most security teams, and may introduce new vulnerabilities. Disabling the application (D) might be an option if it's not critical, but the question implies it's a 'legacy application' that is still in use. Implementing a compensating control (B) like network segmentation or an Intrusion Prevention System (IPS) rule is the most practical and immediate way to reduce the risk associated with an unpatchable critical vulnerability, buying time and reducing exposure.
Why the other options are wrong
- A. Disabling a legacy application might cause significant business disruption and may not be feasible if it's still in use.
- B. Documenting risk acceptance without mitigation is not a responsible action for a critical vulnerability that violates policy.
- D. Developing a custom patch for a legacy application is a complex and time-consuming task, not an immediate action.
Mitigation for Unpatchable Vulnerabilities
Strategies employed to reduce the risk of vulnerabilities for which no direct software patch or fix is available, often involving compensating controls or changes in environment.
- Essential for unsupported or end-of-life software.
- Focuses on reducing exploitability or impact.
- Examples include network segmentation, access control, or IPS rules.
Memory trick: No patch? Build a fence, not just a note saying 'beware'.