Skip to content

Commit 9303de3

Browse files
committed
Update defender-vulnerability-management-faq.md
1 parent c156315 commit 9303de3

File tree

1 file changed

+13
-1
lines changed

1 file changed

+13
-1
lines changed

defender-vulnerability-management/defender-vulnerability-management-faq.md

Lines changed: 13 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ ms.collection:
1414
- Tier1
1515
ms.topic: conceptual
1616
search.appverid: met150
17-
ms.date: 02/08/2025
17+
ms.date: 05/02/2025
1818
---
1919

2020
# Microsoft Defender Vulnerability Management frequently asked questions
@@ -118,6 +118,18 @@ Currently Windows is supported, but coverage will be expanded to more operating
118118

119119
For details on the full list of capabilities across Microsoft Defender Vulnerability Management and Defender for Endpoint, see [Defender Vulnerability Management Capabilities](defender-vulnerability-management-capabilities.md).
120120

121+
### What happens to CVEs that are marked as "won't fix"?
122+
123+
Defender Vulnerability Management currently filters out CVEs marked as "Won't Fix", particularly on Linux platforms, from vulnerability recommendations and security score calculations. This design choice was implemented to reduce noise from non-actionable issues and improve signal-to-noise ratio for security teams.
124+
125+
Certain Linux distributions, such as RHEL, include large numbers of CVEs labeled as "Won't Fix" due to platform-specific or architectural decisions. These CVEs were previously displayed in the Microsoft Defender portal, but they caused confusion and inflated the recommendations list and exposure score. As a result, these were intentionally removed following internal review and Data Subject Rights (DSR) requests.
126+
127+
Current Behavior:
128+
129+
- "Won't Fix" CVEs are not shown in the MDVM portal.
130+
- These CVEs are excluded from vulnerability recommendations and scoring.
131+
- There is no current workaround to view them in the product experience.
132+
121133
### Can customers buy only one capability?
122134

123135
Microsoft Defender Vulnerability Management is available as a vulnerability management solution comprised of multiple premium capabilities.

0 commit comments

Comments
 (0)