logo

Zoom joins the vulnerability fray: Will VISS move the needle on AppSec?

ID: 17b8a3be-ad2c-5031-b8b4-33128364927a

STIX ID: report--17b8a3be-ad2c-5031-b8b4-33128364927a

Feed Name: ReversingLabs Blog

Date Published: 2024-01-09

Date Updated: 2026-04-29

Author: [email protected] (John P. Mello Jr.)

...
...

Zoom introduced the Vulnerability Impact Scoring System (VISS), a free, customizable framework that scores vulnerability impact (0–100) based on 13 defender-focused metrics and only on demonstrated exploitation, complementing rather than replacing CVSS. The article contrasts VISS with EPSS (which predicts exploitation likelihood) and highlights expert perspectives on how combining VISS, EPSS, and CVSS can improve prioritization amid resource constraints, while emphasizing that vulnerability management should be part of a broader security strategy.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.