{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-337-investigate-a-defender-software-version-mismatch-before-calling-it-an-inventory/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-337-investigate-a-defender-software-version-mismatch-before-calling-it-an-inventory/",
        "slug": "dse-20260909-337-investigate-a-defender-software-version-mismatch-before-calling-it-an-inventory",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-337-investigate-a-defender-software-version-mismatch-before-calling-it-an-inventory/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-337-investigate-a-defender-software-version-mismatch-before-calling-it-an-inventory.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-337-investigate-a-defender-software-version-mismatch-before-calling-it-an-inventory/"
        },
        "title": "Investigate a Defender software-version mismatch before calling it an inventory error",
        "summary": "Can Defender legitimately display a software version that differs from the locally installed version string?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:26:19+00:00",
        "modified_at": "2026-09-10T01:40:03+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 256,
        "potentially_affected": "Software version records in Microsoft Defender Vulnerability Management inventory.",
        "dse_recommendation": "Preserve the installed and displayed version strings and reconcile the underlying software evidence before reporting an inaccuracy.",
        "primary_source": {
            "name": "Software inventory - Microsoft Defender Vulnerability Management | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-software-inventory",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Defender Vulnerability Management intentionally normalizes versions for some software to improve cross-device correlation and assessment. Consequently, its displayed string can differ from the installed string without representing a different functional version. Microsoft does not describe every difference as an error. <a href=\"https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-software-inventory\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<p>The device&#8217;s Software Evidence section identifies detection evidence in the registry, on disk or both. The inventory overview refreshes every three to four hours and cannot be manually forced to synchronize. Report inaccuracy provides a route for an actual incorrect software detail or device count. <a href=\"https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-software-inventory\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review software version records in Microsoft Defender Vulnerability Management inventory. This brief concerns reconciliation of an observed version discrepancy, not a claim that every software product is assessed or that all differing strings are equivalent.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends preserving the locally observed version, displayed version, product identity and observation time together. Inspect the device-level evidence before proposing a reinstall or reporting a false vulnerability result. Where normalization does not explain the discrepancy, collect the specific evidence needed for an inaccuracy report. Do not invent a conversion formula from one documented product example and apply it to unrelated software.</p>\n<h2>Verification</h2>\n<p>Compare a known installation with its registry or disk evidence and the portal record after the documented refresh interval. Confirm that the same product and device are being compared. Record whether normalization, delayed inventory or an unresolved discrepancy best fits the evidence, without presenting an inference as a confirmed correction. Preserve both original strings in the final review.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-software-inventory\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Software inventory</a>.</p>",
        "content_text": "Source facts\nDefender Vulnerability Management intentionally normalizes versions for some software to improve cross-device correlation and assessment. Consequently, its displayed string can differ from the installed string without representing a different functional version. Microsoft does not describe every difference as an error. Microsoft Learn.\nThe device’s Software Evidence section identifies detection evidence in the registry, on disk or both. The inventory overview refreshes every three to four hours and cannot be manually forced to synchronize. Report inaccuracy provides a route for an actual incorrect software detail or device count. Microsoft Learn.\nApplicability\nReview software version records in Microsoft Defender Vulnerability Management inventory. This brief concerns reconciliation of an observed version discrepancy, not a claim that every software product is assessed or that all differing strings are equivalent.\nDSE recommendation\nDSE recommends preserving the locally observed version, displayed version, product identity and observation time together. Inspect the device-level evidence before proposing a reinstall or reporting a false vulnerability result. Where normalization does not explain the discrepancy, collect the specific evidence needed for an inaccuracy report. Do not invent a conversion formula from one documented product example and apply it to unrelated software.\nVerification\nCompare a known installation with its registry or disk evidence and the portal record after the documented refresh interval. Confirm that the same product and device are being compared. Record whether normalization, delayed inventory or an unresolved discrepancy best fits the evidence, without presenting an inference as a confirmed correction. Preserve both original strings in the final review.\nOfficial references\nMicrosoft Learn: Software inventory.",
        "content_markdown": "## Source facts\n\nDefender Vulnerability Management intentionally normalizes versions for some software to improve cross-device correlation and assessment. Consequently, its displayed string can differ from the installed string without representing a different functional version. Microsoft does not describe every difference as an error. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-software-inventory).\n\nThe device’s Software Evidence section identifies detection evidence in the registry, on disk or both. The inventory overview refreshes every three to four hours and cannot be manually forced to synchronize. Report inaccuracy provides a route for an actual incorrect software detail or device count. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-software-inventory).\n\n## Applicability\n\nReview software version records in Microsoft Defender Vulnerability Management inventory. This brief concerns reconciliation of an observed version discrepancy, not a claim that every software product is assessed or that all differing strings are equivalent.\n\n## DSE recommendation\n\nDSE recommends preserving the locally observed version, displayed version, product identity and observation time together. Inspect the device-level evidence before proposing a reinstall or reporting a false vulnerability result. Where normalization does not explain the discrepancy, collect the specific evidence needed for an inaccuracy report. Do not invent a conversion formula from one documented product example and apply it to unrelated software.\n\n## Verification\n\nCompare a known installation with its registry or disk evidence and the portal record after the documented refresh interval. Confirm that the same product and device are being compared. Record whether normalization, delayed inventory or an unresolved discrepancy best fits the evidence, without presenting an inference as a confirmed correction. Preserve both original strings in the final review.\n\n## Official references\n\n[Microsoft Learn: Software inventory](https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-software-inventory)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-337-investigate-a-defender-software-version-mismatch-before-calling-it-an-inventory/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-337-investigate-a-defender-software-version-mismatch-before-calling-it-an-inventory/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-337-investigate-a-defender-software-version-mismatch-before-calling-it-an-inventory/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Investigate a Defender software-version mismatch before calling it an inventory error",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-337-investigate-a-defender-software-version-mismatch-before-calling-it-an-inventory/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-337-investigate-a-defender-software-version-mismatch-before-calling-it-an-inventory/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-337-investigate-a-defender-software-version-mismatch-before-calling-it-an-inventory/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-337-investigate-a-defender-software-version-mismatch-before-calling-it-an-inventory/",
                "headline": "Investigate a Defender software-version mismatch before calling it an inventory error",
                "description": "Can Defender legitimately display a software version that differs from the locally installed version string?",
                "abstract": "Can Defender legitimately display a software version that differs from the locally installed version string?",
                "articleBody": "Source facts\nDefender Vulnerability Management intentionally normalizes versions for some software to improve cross-device correlation and assessment. Consequently, its displayed string can differ from the installed string without representing a different functional version. Microsoft does not describe every difference as an error. Microsoft Learn.\nThe device’s Software Evidence section identifies detection evidence in the registry, on disk or both. The inventory overview refreshes every three to four hours and cannot be manually forced to synchronize. Report inaccuracy provides a route for an actual incorrect software detail or device count. Microsoft Learn.\nApplicability\nReview software version records in Microsoft Defender Vulnerability Management inventory. This brief concerns reconciliation of an observed version discrepancy, not a claim that every software product is assessed or that all differing strings are equivalent.\nDSE recommendation\nDSE recommends preserving the locally observed version, displayed version, product identity and observation time together. Inspect the device-level evidence before proposing a reinstall or reporting a false vulnerability result. Where normalization does not explain the discrepancy, collect the specific evidence needed for an inaccuracy report. Do not invent a conversion formula from one documented product example and apply it to unrelated software.\nVerification\nCompare a known installation with its registry or disk evidence and the portal record after the documented refresh interval. Confirm that the same product and device are being compared. Record whether normalization, delayed inventory or an unresolved discrepancy best fits the evidence, without presenting an inference as a confirmed correction. Preserve both original strings in the final review.\nOfficial references\nMicrosoft Learn: Software inventory.",
                "datePublished": "2026-09-10T00:26:19+00:00",
                "dateModified": "2026-09-10T01:40:03+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-337-investigate-a-defender-software-version-mismatch-before-calling-it-an-inventory/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-337-investigate-a-defender-software-version-mismatch-before-calling-it-an-inventory/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Investigate a Defender software-version mismatch before calling it an inventory error"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 256,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Software inventory - Microsoft Defender Vulnerability Management | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-software-inventory"
                }
            }
        ]
    }
}