Why defender for endpoints say that does't exist the CVE-2013-3900 and when I see the REG entry, they really exist ?
Andrew Matheus da Silva Lobo
5
Reputation points
In the Microsoft Defender for Endpoint (MDE) console, when I search for CVE-2013-3900 (WinVerifyTrust), the results show zero vulnerable endpoints. However, mitigating this CVE primarily involves creating a registry entry, and in all the endpoints I’ve analyzed, none have this registry entry in place. Other vulnerability assessment tools detect this vulnerability, but MDE does not.
My question is: Why does MDE fail to recognize the vulnerability while other tools do ?
Sign in to answer