Vulnerability Report
A read only view of the CVEs Microsoft Defender has found across your devices, one row per CVE, with any exception recorded against it shown alongside. Where CVE Management is where you work the vulnerabilities, this page is where you report on them: it carries the exception detail, including who granted it, why, and when it lapses.
Table Details
Cve Id
The CVE identifier. Each row is one CVE.
Vulnerability Severity Level
Microsoft's severity rating for the vulnerability.
Exploitability Level
Microsoft's assessment of how exploitable the vulnerability is.
Devices
How many affected devices were counted.
Software Name
The vulnerable software.
Software Vendor
The vendor of the vulnerable software.
Software Version
The version the vulnerability was found on.
Exception Status
How widely an exception covers the CVE: None where none is recorded, All where a global exception applies, and Partial where only some of the affected tenants are covered.
Exception Type
The reason category chosen when the exception was recorded, per tenant.
Exception Comment
The justification written when the exception was recorded, per tenant.
Exception Created By
Who recorded the exception, per tenant.
Exception Readable Date
When the exception was recorded, per tenant.
Exception Expiry
When the exception lapses, per tenant. Empty where the exception was recorded without an expiry.
The exception columns hold one entry per tenant, so a CVE excepted in several tenants shows several values in a single cell. Expand the cell to see which tenant each value belongs to.
Feature Requests/Ideas
We value your feedback and ideas. Please raise any feature requests on GitHub.
Last updated
Was this helpful?

