Microsoft Defender Vulnerability Management
General

Tvm Software Inventory

In brief

The documentation now describes vulnerability reporting for supported Microsoft Store applications, including Microsoft Store-tagged CVE evidence and suggested queries.

What Defender admins need to know

Administrators can use the tag and query to identify affected Store apps and should manage their versions through the Microsoft Store.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

:::image type="content" alt-text="Software evidence example of Microsoft Edge showing evidence registry path as seen on a device page" source="/defender/media/defender-vulnerability-management/tvm-sw-inventory-evidence-small.png" lightbox="/defender/media/defender-vulnerability-management/tvm-sw-inventory-evidence.png":::

Software pages

Microsoft Store applications (Preview)

You can view software pages inDefender Vulnerability Management reports vulnerabilities detected on applications installed via the Microsoft Defender portalMicrosoft Store. CVE evidence for these applications includes the Microsoft Store tag along with a suggested query showing the vulnerable application, version, and file location.

Supported applications include:

  • Microsoft Teams
  • Mozilla Firefox
  • WhatsApp
  • Slack
  • Dropbox
  • DuckDuckGo
  • Dell Command
  • HP Smart
  • HP Support Assistant
  • Dell SupportAssist for Home PCs
  • NVIDIA Control Panel

Software pages

You can view software pages in the Microsoft Defender portal a few different ways: