Skip to content

Vulnerability Management - Macs without actively exploited macOS vulnerabilities

Description

The percentage of Macs running a macOS version with no known actively exploited vulnerabilities that a later release has already fixed, measuring how quickly critical operating system updates reach the fleet.

How we measure it

Find all Macs managed by Kandji that checked in within the last 30 days. Using Apple's security release notes (via macadmins.io), a Mac is considered non-compliant if a later release of its macOS major version fixes a CVE that Apple reports as actively exploited.

Meta Data

Attribute Value
Metric id vm_macos_exploited_cves
Category Vulnerability Management
SLO 90.00% - 98.00%
Weight 0.8
Type risk

References

Framework Ref Domain Control
ISO 27001:2022 A.8.8 8 Technological controls Management of technical vulnerabilities
CIS 8.1 7.3 Continuous Vulnerability Management Perform Automated Operating System Patch Management
CIS 8.1 7.7 Continuous Vulnerability Management Remediate Detected Vulnerabilities
NIST CSF v2.0 ID.RA-01 Risk Assessment (ID.RA) ID.RA-01: Vulnerabilities in assets are identified, validated, and recorded
Essential8-ML1 ISM-1695 Patch operating systems Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release.
Essential8-ML2 ISM-1695 Patch operating systems Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release.

Code

WITH macs AS (
  SELECT details.device_name || ' (' || details.serial_number || ')' AS device_name, details.os_version,
         list_transform(string_split(details.os_version, '.'), part -> TRY_CAST(part AS INTEGER)) AS version
  FROM {{ ref('kandji_device_details') }} AS details
  JOIN {{ ref('kandji_devices') }} AS devices ON devices.device_id = details.device_id
  WHERE details.platform = 'Mac'
    AND NOT devices.is_missing AND NOT devices.is_removed
    AND CURRENT_DATE - CAST(devices.last_check_in AS DATE) <= 30
),
fixes AS (
  SELECT product_version, cve_id,
         list_transform(string_split(product_version, '.'), part -> CAST(part AS INTEGER)) AS version
  FROM {{ ref('macadmins_macos_cves') }}
  WHERE exploited
),
exposure AS (
  SELECT macs.device_name, macs.os_version,
         count(DISTINCT fixes.cve_id) AS exploited_cves,
         string_agg(DISTINCT fixes.cve_id, ', ') AS cve_ids,
         max(fixes.version) AS fixed_in
  FROM macs
  LEFT JOIN fixes
    ON fixes.version[1] = macs.version[1]
    AND fixes.version > macs.version
  GROUP BY 1, 2
)
SELECT
  device_name AS resource,
  'host' AS resource_type,
  CASE WHEN exploited_cves = 0 THEN 1 ELSE 0 END AS compliance,
  CASE
    WHEN exploited_cves = 0 THEN 'macOS ' || os_version || ': no known exploited CVEs fixed in a later ' || CAST(split_part(os_version, '.', 1) AS VARCHAR) || '.x release'
    ELSE 'macOS ' || os_version || ': ' || CAST(exploited_cves AS VARCHAR) || ' actively exploited CVE(s) fixed in a later release, update to macOS ' || array_to_string(fixed_in, '.') || ' (' || cve_ids || ')'
  END AS detail
FROM exposure