Microsoft Defender for Cloud
Cloud and workloads

View and remediate vulnerabilities for running containers

In brief

The article was revised for clearer wording, updated metadata, simplified prerequisite instructions, and refreshed links and step descriptions. The documented component combinations and recommendation workflow were clarified.

What Defender admins need to know

Administrators can use the updated instructions to review and remediate Kubernetes container vulnerabilities; no configuration change is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

View and remediate vulnerabilities for running containers

Defender for Cloud helps you identifyfind and prioritizefix vulnerabilities in images currently used bythat your Kubernetes workloads running on Kubernetes clusters.use.

To generatecreate these findings, Defender for Cloud first builds an inventorya list of your Kubernetes workloads by usingworkloads. It uses supported discovery and protection components, and correlatescomponents to do this. Then it matches that inventory withlist against known vulnerability data for the images used by those workloads.workloads run.

Vulnerability findingsFindings for running containers are shownappear as security recommendations in Defender for Cloud.recommendations. The following steps in this article use the Flat list recommendations view, which shows recommendationsresults at the affected-resource level. Learn more about reviewing recommendations by title or by resource.

Prerequisites

Before you begin, make sure thatenable Defender for Containers or Defender CSPM is enabled on your subscription withsubscription. Turn on one of the followingthese component combinations toggled on:sets:

  • Registry access and either Kubernetes API access or Defender sensor to map registry-. This option links scanned registry images to running workloads.
  • Agentless scanning for machines and either Kubernetes API access or Defender sensor. This option checks for registry-agnostic runtime vulnerability assessment.vulnerabilities without a registry.

View vulnerabilities for running containers

  1. Select a recommendation.

  2. Review the recommendation details, including the risk information, remediation guidance,info, fix steps, and recommendation metadata.

  3. Select the Associated CVEs tab to reviewsee the CVEs associated with the recommendation.for that item.

  4. Select a CVE to view details such asits severity, affected components, and fix version information.version.

Related content

\ No newline at end of file