Microsoft Defender Vulnerability Management gets a smarter exposure score

Source: Help Net Security

Author: Anamarija Pogorelec

URL: https://www.helpnetsecurity.com/2026/06/01/microsoft-defender-exposure-score-update/

https://www.helpnetsecurity.com/2026/06/01/microsoft-defender-exposure-score-update/

ONE SENTENCE SUMMARY:

Microsoft Defender Vulnerability Management updates exposure scoring using exploitability signals and asset context to better prioritize remediation actions.

MAIN POINTS:

  1. Updated exposure score shifts focus from vulnerability severity to remediation prioritization.
  2. Model combines vulnerability risk, exploitability signals, and asset context for representativeness.
  3. EPSS is used to estimate 30-day exploitation likelihood for CVEs.
  4. Normalized CVE data from multiple sources improves scoring consistency.
  5. Device exposure reflects all vulnerabilities on a device, weighted by risk and context.
  6. Remediation activities more directly reduce device exposure scores under the new model.
  7. Asset context includes internet-facing status and criticality to influence prioritization.
  8. Identical vulnerabilities can warrant different responses depending on affected asset exposure and business value.
  9. Organization-level score is derived from individual asset scores for better environment-wide representation.
  10. Asset-CVE-level remediation impact calculations improve prediction and tracking of score changes.

TAKEAWAYS:

  1. Prioritization improves by emphasizing “where to fix first” rather than only “how severe.”
  2. Exploitability-driven scoring helps surface vulnerabilities more likely to be exploited soon.
  3. Context-aware weighting concentrates attention on high-risk, internet-exposed, or critical devices.
  4. Score shifts after enabling the model require treating results as a new, non-comparable baseline.
  5. Daily score updates and 24-hour remediation lag affect how quickly improvements appear in reporting.