Microsoft Defender Vulnerability Management
General

Hardware and firmware assessment

In brief

The article now explicitly refers to Microsoft Defender XDR plus Microsoft Defender for Identity preview customers and clarifies that BIOS recommendations appear when a specific BIOS version is installed on at least 5% of devices across organizations. Metadata was also updated.

What Defender admins need to know

Administrators can more accurately interpret where BIOS CVEs appear and when BIOS update recommendations are generated; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Hardware and firmware assessment

To actively search for processor and BIOS vulnerabilities:

  1. Search for 'BIOS' CVEs that relate to the processor or BIOS will be returned. This might be available either on the Vulnerabilities page or from the Weaknesses page, depending on if you're an XDR/MDIa Microsoft Defender XDR + Microsoft Defender for Identity (XDR/MDI) preview customer. For more information, see Microsoft Defender Vulnerability Management and Microsoft Security Exposure Management integration.
  2. Select an item from the list to open a flyout panel with more details on the CVE.

On individual devices view processor and BIOS CVEs by selecting the Discovered vulnerabilities tab. Select a CVE to see a flyout panel with more information:

In the Recommendations page, filter on Remediation type 'Firmware update'.

Recommendations appear to update a specific BIOS version if it'sthat BIOS version is installed on at least 5% of devices across all organizations.

:::image type="content" source="/defender/media/defender-vulnerability-management/firmware-recommendations.png" alt-text="Screenshot of firmware recommendations page":::