NIST 800-53 r5 · Controls catalogue · Family AC
AC-25Reference Monitor
Implement a reference monitor for {{ insert: param, ac-25_odp }} that is tamperproof, always invoked, and small enough to be subject to analysis and testing, the completeness of which can be assured.
Last updated: 22 August 2026 14:14 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (8)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-862 | Missing Authorization | 10,200+ | Always invoking the reference monitor prevents missing authorization checks for protected resources. |
CWE-284 | Improper Access Control | 6,900+ | Provides a tamperproof, always-invoked, and verifiable mechanism to enforce access control policies. |
CWE-863 | Incorrect Authorization | 3,900+ | The small, testable reference monitor reduces the likelihood of incorrect authorization implementations. |
CWE-269 | Improper Privilege Management | 3,400+ | Enforces proper privilege management by requiring all decisions through the verified reference monitor. |
CWE-306 | Missing Authentication for Critical Function | 3,300+ | Guarantees critical functions are protected by mandatory invocation of the access control mechanism. |
CWE-285 | Improper Authorization | 1,500+ | Ensures authorization decisions are always performed by a complete and analyzable reference monitor. |
CWE-693 | Protection Mechanism Failure | 700+ | Implements a reliable, tamperproof protection mechanism whose completeness can be assured. |
CWE-425 | Direct Request ('Forced Browsing') | 200+ | Forces all accesses through the reference monitor, preventing direct or forced requests that bypass checks. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2024-1709 KEV UPD | 10.0 | 10.0 | 0.9996 | good |
CVE-2024-27198 KEV UPD | 9.9 | 9.8 | 0.9994 | good |
CVE-2024-10924 UPD | 9.9 | 9.8 | 0.8203 | good |
CVE-2024-55591 KEV UPD | 9.9 | 9.8 | 0.9826 | good |
CVE-2025-2746 KEV UPD | 9.9 | 9.8 | 0.5905 | good |
CVE-2025-2747 KEV UPD | 9.9 | 9.8 | 0.9238 | good |
CVE-2024-56325 UPD | 9.9 | 9.8 | 0.7867 | good |
CVE-2025-57819 KEV UPD | 9.9 | 9.8 | 0.8827 | good |
CVE-2026-23760 KEV UPD | 9.9 | 9.8 | 0.9627 | good |
CVE-2026-24858 KEV UPD | 9.9 | 9.8 | 0.8584 | good |
CVE-2024-23917 UPD | 9.4 | 9.8 | 0.5373 | good |
CVE-2024-7314 UPD | 9.4 | 9.8 | 0.5147 | good |
CVE-2024-50379 UPD | 9.2 | 9.8 | 0.4431 | good |
CVE-2025-22224 KEV UPD | 9.2 | 9.3 | 0.0156 | good |
CVE-2024-10081 UPD | 9.1 | 10.0 | 0.3912 | good |
CVE-2022-25369 UPD | 9.1 | 9.8 | 0.4074 | good |
CVE-2026-20079 UPD | 9.1 | 10.0 | 0.3767 | good |
CVE-2026-10523 UPD | 9.0 | 9.9 | 0.5187 | good |
CVE-2024-33610 UPD | 8.8 | 9.1 | 0.4584 | good |
CVE-2026-1603 KEV UPD | 8.8 | 8.6 | 0.8056 | good |
CVE-2025-24472 KEV UPD | 8.7 | 8.1 | 0.0358 | good |
CVE-2026-18577 KEV | 8.7 | 8.1 | 0.0410 | good |
CVE-2024-39309 UPD | 8.5 | 9.8 | 0.2017 | good |
CVE-2025-34026 KEV UPD | 8.5 | 7.5 | 0.8194 | good |
CVE-2025-38352 KEV UPD | 8.5 | 7.8 | 0.0128 | good |