Beyond CVE China’s Dual Vulnerability Databases Reveal a Different Disclosure Timeline
The development of a distinct vulnerability disclosure ecosystem within China has introduced a new layer to the global threat landscape.
The development of a distinct vulnerability disclosure ecosystem within China has introduced a new layer to the global threat landscape.
Differentiated Vulnerability Databases
In contrast to the centralized CVE system internationally utilized, China operates two separate databases—the CNVD and CNNVD. These databases maintain different disclosure timelines and priorities.
The dual structure allows for vulnerabilities to remain undisclosed to Western defenders for extended periods. This creates informational asymmetry, enabling threat actors to exploit vulnerabilities in widely used software such as Microsoft OneDrive before global patch cycles can respond.
The delay in publicly releasing vulnerability data significantly impacts enterprise security teams, which rely on timely data to prioritize remediation efforts. When vulnerabilities are listed in Chinese databases months before they appear in the U.S. National Vulnerability Database (NVD), organizations face a period of exposure to active threats.
For example, a Microsoft OneDrive DLL hijacking vulnerability was cataloged in Chinese systems well before a comparable CVE was documented internationally. This delay allows exploitation of these vulnerabilities, often referred to as "Red Vulns," against unsuspecting targets, bypassing standard detection protocols.
Analyses of publication timestamps across both the CNVD and CNNVD reveal these discrepancies. The CNNVD largely mirrors the MITRE CVE list, while the CNVD often operates independently with unique entries and timelines.
The development of a distinct vulnerability disclosure ecosystem within China has introduced a new layer to the global threat landscape.
Despite the volume of vulnerabilities tracked by Chinese authorities aligning with global standards, the strategic latency in the disclosure process turns vulnerability data into a national security asset rather than a public resource.
A systematic delay in releasing high-severity vulnerability details is a concerning aspect of this ecosystem. This persistence tactic effectively masks the infection mechanisms of new exploits, depriving global defenders of necessary Indicators of Compromise (IOCs) to detect early-stage attacks.
Moreover, a significant percentage of CNVD entries do not immediately map to a CVE, creating a "shadow" inventory of security flaws. To address this, security teams should expand their intelligence sources beyond the NVD to include international databases for a comprehensive threat assessment.
CVE / ID Vulnerability Name Severity Key Observation
CVE-2024-33698 Generic Vulnerability High Mapped to CNVD entry; published later in CVE.
CNVD-2024-xxxxx OneDrive DLL Hijacking High Similar to CVE-2021-40444 but published earlier.
CNVD-202-35587 Bitcoin Core DoS Medium Example of "Event-based" vulnerability in CNVD.
CVE-2021-40444 MSHTML RCE Critical Used as a reference for delay analysis.
Based on reporting by Cyber Security News.
