{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-366-identify-the-updater-before-blocking-a-vulnerable-application-version/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-366-identify-the-updater-before-blocking-a-vulnerable-application-version/",
        "slug": "dse-20260909-366-identify-the-updater-before-blocking-a-vulnerable-application-version",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-366-identify-the-updater-before-blocking-a-vulnerable-application-version/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-366-identify-the-updater-before-blocking-a-vulnerable-application-version.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-366-identify-the-updater-before-blocking-a-vulnerable-application-version/"
        },
        "title": "Identify the updater before blocking a vulnerable application version",
        "summary": "Can a vulnerable application still update when its main executable is blocked?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:25:50+00:00",
        "modified_at": "2026-09-10T02:01:56+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 260,
        "potentially_affected": "Supported non-Microsoft applications on Windows 11 using Defender Vulnerability Management block mitigations.",
        "dse_recommendation": "Determine whether updating uses a separate executable before approving a temporary vulnerable-version block.",
        "primary_source": {
            "name": "Block vulnerable applications with Microsoft Defender Vulnerability Management - Microsoft Defender Vulnerability Management | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-block-vuln-apps",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Defender Vulnerability Management blocks vulnerable application versions through executable file-hash indicators. Microsoft explains that a separate updater executable is not blocked by the main application&#8217;s block, but some applications need the main executable to update. Those designs require a different remediation path. <a href=\"https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-block-vuln-apps\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<p>The mitigation requires active-mode Defender Antivirus, cloud-delivered protection and the Allow or block file feature. Passive mode and EDR in block mode do not provide this execution blocking. Microsoft applications, operating-system recommendations and macOS/Linux application recommendations are excluded. Blocking is a best-attempt mitigation, not a guarantee. <a href=\"https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-block-vuln-apps\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review supported non-Microsoft applications on Windows 11 using Defender Vulnerability Management block mitigations. Confirm the current application and component prerequisites before deciding that the mitigation is available.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends identifying the actual update executable and its dependency on the blocked program before activating the temporary control. Ask the application owner to provide an approved update method that preserves needed local data. If ordinary updating depends on the blocked binary, arrange a controlled remediation path with security approval rather than instructing users to bypass the block routinely. Keep mitigation ownership linked to the permanent fix.</p>\n<h2>Verification</h2>\n<p>Test the approved updater with a representative installation while the intended vulnerable version remains blocked. Confirm the new version and the application&#8217;s required business function afterward. Inspect the scoped indicators and remediation activity rather than judging success from a toast notification. Record any update failure separately from a blocking failure, and close the temporary mitigation only through the approved remediation decision.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-block-vuln-apps\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Block vulnerable applications</a>.</p>",
        "content_text": "Source facts\nDefender Vulnerability Management blocks vulnerable application versions through executable file-hash indicators. Microsoft explains that a separate updater executable is not blocked by the main application’s block, but some applications need the main executable to update. Those designs require a different remediation path. Microsoft Learn.\nThe mitigation requires active-mode Defender Antivirus, cloud-delivered protection and the Allow or block file feature. Passive mode and EDR in block mode do not provide this execution blocking. Microsoft applications, operating-system recommendations and macOS/Linux application recommendations are excluded. Blocking is a best-attempt mitigation, not a guarantee. Microsoft Learn.\nApplicability\nReview supported non-Microsoft applications on Windows 11 using Defender Vulnerability Management block mitigations. Confirm the current application and component prerequisites before deciding that the mitigation is available.\nDSE recommendation\nDSE recommends identifying the actual update executable and its dependency on the blocked program before activating the temporary control. Ask the application owner to provide an approved update method that preserves needed local data. If ordinary updating depends on the blocked binary, arrange a controlled remediation path with security approval rather than instructing users to bypass the block routinely. Keep mitigation ownership linked to the permanent fix.\nVerification\nTest the approved updater with a representative installation while the intended vulnerable version remains blocked. Confirm the new version and the application’s required business function afterward. Inspect the scoped indicators and remediation activity rather than judging success from a toast notification. Record any update failure separately from a blocking failure, and close the temporary mitigation only through the approved remediation decision.\nOfficial references\nMicrosoft Learn: Block vulnerable applications.",
        "content_markdown": "## Source facts\n\nDefender Vulnerability Management blocks vulnerable application versions through executable file-hash indicators. Microsoft explains that a separate updater executable is not blocked by the main application’s block, but some applications need the main executable to update. Those designs require a different remediation path. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-block-vuln-apps).\n\nThe mitigation requires active-mode Defender Antivirus, cloud-delivered protection and the Allow or block file feature. Passive mode and EDR in block mode do not provide this execution blocking. Microsoft applications, operating-system recommendations and macOS/Linux application recommendations are excluded. Blocking is a best-attempt mitigation, not a guarantee. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-block-vuln-apps).\n\n## Applicability\n\nReview supported non-Microsoft applications on Windows 11 using Defender Vulnerability Management block mitigations. Confirm the current application and component prerequisites before deciding that the mitigation is available.\n\n## DSE recommendation\n\nDSE recommends identifying the actual update executable and its dependency on the blocked program before activating the temporary control. Ask the application owner to provide an approved update method that preserves needed local data. If ordinary updating depends on the blocked binary, arrange a controlled remediation path with security approval rather than instructing users to bypass the block routinely. Keep mitigation ownership linked to the permanent fix.\n\n## Verification\n\nTest the approved updater with a representative installation while the intended vulnerable version remains blocked. Confirm the new version and the application’s required business function afterward. Inspect the scoped indicators and remediation activity rather than judging success from a toast notification. Record any update failure separately from a blocking failure, and close the temporary mitigation only through the approved remediation decision.\n\n## Official references\n\n[Microsoft Learn: Block vulnerable applications](https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-block-vuln-apps)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-366-identify-the-updater-before-blocking-a-vulnerable-application-version/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-366-identify-the-updater-before-blocking-a-vulnerable-application-version/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-366-identify-the-updater-before-blocking-a-vulnerable-application-version/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Identify the updater before blocking a vulnerable application version",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-366-identify-the-updater-before-blocking-a-vulnerable-application-version/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-366-identify-the-updater-before-blocking-a-vulnerable-application-version/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-366-identify-the-updater-before-blocking-a-vulnerable-application-version/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-366-identify-the-updater-before-blocking-a-vulnerable-application-version/",
                "headline": "Identify the updater before blocking a vulnerable application version",
                "description": "Can a vulnerable application still update when its main executable is blocked?",
                "abstract": "Can a vulnerable application still update when its main executable is blocked?",
                "articleBody": "Source facts\nDefender Vulnerability Management blocks vulnerable application versions through executable file-hash indicators. Microsoft explains that a separate updater executable is not blocked by the main application’s block, but some applications need the main executable to update. Those designs require a different remediation path. Microsoft Learn.\nThe mitigation requires active-mode Defender Antivirus, cloud-delivered protection and the Allow or block file feature. Passive mode and EDR in block mode do not provide this execution blocking. Microsoft applications, operating-system recommendations and macOS/Linux application recommendations are excluded. Blocking is a best-attempt mitigation, not a guarantee. Microsoft Learn.\nApplicability\nReview supported non-Microsoft applications on Windows 11 using Defender Vulnerability Management block mitigations. Confirm the current application and component prerequisites before deciding that the mitigation is available.\nDSE recommendation\nDSE recommends identifying the actual update executable and its dependency on the blocked program before activating the temporary control. Ask the application owner to provide an approved update method that preserves needed local data. If ordinary updating depends on the blocked binary, arrange a controlled remediation path with security approval rather than instructing users to bypass the block routinely. Keep mitigation ownership linked to the permanent fix.\nVerification\nTest the approved updater with a representative installation while the intended vulnerable version remains blocked. Confirm the new version and the application’s required business function afterward. Inspect the scoped indicators and remediation activity rather than judging success from a toast notification. Record any update failure separately from a blocking failure, and close the temporary mitigation only through the approved remediation decision.\nOfficial references\nMicrosoft Learn: Block vulnerable applications.",
                "datePublished": "2026-09-10T00:25:50+00:00",
                "dateModified": "2026-09-10T02:01:56+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-366-identify-the-updater-before-blocking-a-vulnerable-application-version/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-366-identify-the-updater-before-blocking-a-vulnerable-application-version/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Identify the updater before blocking a vulnerable application version"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 260,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Block vulnerable applications with Microsoft Defender Vulnerability Management - Microsoft Defender Vulnerability Management | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-block-vuln-apps"
                }
            }
        ]
    }
}