Identifying OS Patches and Updates by Severity in Azure

$@chin 145 Reputation points
2025-02-07T13:33:18.17+00:00

Hello,

How can I identify operating system patches or available OS updates on both Linux and Windows Azure VMs based on severity within the Azure Portal, Azure Update Manager, or Microsoft Defender for Cloud ?

In Azure Update Manager, updates are displayed by classification, but it doesn't seem to provide information on severity.
In Defender for Cloud, vulnerabilities are categorized into three levels: High, Medium, and Low, based on threat intelligence, but these don't necessarily reflect the CVSS (Common Vulnerability Scoring System) scores.

How can I map this information or use Azure tools to determine the severity of patches or updates according to CVSS scores, and is there a way to generate a detailed report on this?

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
8,337 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,681 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,487 questions
Azure Update Manager
Azure Update Manager
An Azure service to centrally manages updates and compliance at scale.
342 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.