{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-463-preserve-the-link-between-a-temporary-zero-day-name-and-its-later-cve-identifier/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-463-preserve-the-link-between-a-temporary-zero-day-name-and-its-later-cve-identifier/",
        "slug": "dse-20260909-463-preserve-the-link-between-a-temporary-zero-day-name-and-its-later-cve-identifier",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-463-preserve-the-link-between-a-temporary-zero-day-name-and-its-later-cve-identifier/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-463-preserve-the-link-between-a-temporary-zero-day-name-and-its-later-cve-identifier.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-463-preserve-the-link-between-a-temporary-zero-day-name-and-its-later-cve-identifier/"
        },
        "title": "Preserve the link between a temporary zero-day name and its later CVE identifier",
        "summary": "How should a vulnerability case remain traceable when Defender replaces its temporary TVM name with a CVE?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:24:13+00:00",
        "modified_at": "2026-09-10T02:08:04+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 240,
        "potentially_affected": "Defender Vulnerability Management records for known zero-day vulnerabilities that initially lack an assigned CVE identifier.",
        "dse_recommendation": "Keep the temporary identifier as an alias in the existing vulnerability case when the official CVE becomes available.",
        "primary_source": {
            "name": "Mitigate zero-day vulnerabilities - Microsoft Defender Vulnerability Management | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-zero-day-vulnerabilities",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Defender Vulnerability Management can display a zero-day without a CVE under a temporary TVM-XXXX-XXXX name. It replaces that name when a CVE is assigned, while keeping the earlier name searchable in the side panel. When a patch becomes available, the recommendation changes to Update and the zero-day tag is removed. The service displays only zero-days about which it has information. <a href=\"https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-zero-day-vulnerabilities\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this continuity check for an already tracked vulnerability whose displayed identifier or label changes. A naming transition and patch availability are lifecycle information; neither is evidence that the organization&#8217;s affected installations were repaired.</p>\n<h2>DSE recommendation</h2>\n<p>Keep the temporary identifier as an alias in the existing vulnerability case when the official CVE becomes available. Ask the case owner to connect earlier mitigation decisions, affected-software evidence and subsequent update work to that same record. Avoid closing the case merely because its old display label disappears, and investigate a possible duplicate before creating another independently tracked item.</p>\n<h2>Verification</h2>\n<p>Search for the retained temporary name and compare the resulting record with the assigned CVE and software scope. Record the identifier transition separately from the patch-deployment decision. If an update is now recommended, confirm which affected installations have actually received the approved remediation and which remain exceptions. Keep unverified installations open; the acceptance result is a reconciled case history and observed remediation state, not simply a cleaner zero-day filter.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-zero-day-vulnerabilities\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Zero-day vulnerability handling</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nDefender Vulnerability Management can display a zero-day without a CVE under a temporary TVM-XXXX-XXXX name. It replaces that name when a CVE is assigned, while keeping the earlier name searchable in the side panel. When a patch becomes available, the recommendation changes to Update and the zero-day tag is removed. The service displays only zero-days about which it has information. Microsoft Learn.\nApplicability\nUse this continuity check for an already tracked vulnerability whose displayed identifier or label changes. A naming transition and patch availability are lifecycle information; neither is evidence that the organization’s affected installations were repaired.\nDSE recommendation\nKeep the temporary identifier as an alias in the existing vulnerability case when the official CVE becomes available. Ask the case owner to connect earlier mitigation decisions, affected-software evidence and subsequent update work to that same record. Avoid closing the case merely because its old display label disappears, and investigate a possible duplicate before creating another independently tracked item.\nVerification\nSearch for the retained temporary name and compare the resulting record with the assigned CVE and software scope. Record the identifier transition separately from the patch-deployment decision. If an update is now recommended, confirm which affected installations have actually received the approved remediation and which remain exceptions. Keep unverified installations open; the acceptance result is a reconciled case history and observed remediation state, not simply a cleaner zero-day filter.\nOfficial references\nMicrosoft Learn: Zero-day vulnerability handling. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nDefender Vulnerability Management can display a zero-day without a CVE under a temporary TVM-XXXX-XXXX name. It replaces that name when a CVE is assigned, while keeping the earlier name searchable in the side panel. When a patch becomes available, the recommendation changes to Update and the zero-day tag is removed. The service displays only zero-days about which it has information. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-zero-day-vulnerabilities).\n\n## Applicability\n\nUse this continuity check for an already tracked vulnerability whose displayed identifier or label changes. A naming transition and patch availability are lifecycle information; neither is evidence that the organization’s affected installations were repaired.\n\n## DSE recommendation\n\nKeep the temporary identifier as an alias in the existing vulnerability case when the official CVE becomes available. Ask the case owner to connect earlier mitigation decisions, affected-software evidence and subsequent update work to that same record. Avoid closing the case merely because its old display label disappears, and investigate a possible duplicate before creating another independently tracked item.\n\n## Verification\n\nSearch for the retained temporary name and compare the resulting record with the assigned CVE and software scope. Record the identifier transition separately from the patch-deployment decision. If an update is now recommended, confirm which affected installations have actually received the approved remediation and which remain exceptions. Keep unverified installations open; the acceptance result is a reconciled case history and observed remediation state, not simply a cleaner zero-day filter.\n\n## Official references\n\n[Microsoft Learn: Zero-day vulnerability handling](https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-zero-day-vulnerabilities). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-463-preserve-the-link-between-a-temporary-zero-day-name-and-its-later-cve-identifier/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-463-preserve-the-link-between-a-temporary-zero-day-name-and-its-later-cve-identifier/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-463-preserve-the-link-between-a-temporary-zero-day-name-and-its-later-cve-identifier/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Preserve the link between a temporary zero-day name and its later CVE identifier",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-463-preserve-the-link-between-a-temporary-zero-day-name-and-its-later-cve-identifier/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-463-preserve-the-link-between-a-temporary-zero-day-name-and-its-later-cve-identifier/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-463-preserve-the-link-between-a-temporary-zero-day-name-and-its-later-cve-identifier/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-463-preserve-the-link-between-a-temporary-zero-day-name-and-its-later-cve-identifier/",
                "headline": "Preserve the link between a temporary zero-day name and its later CVE identifier",
                "description": "How should a vulnerability case remain traceable when Defender replaces its temporary TVM name with a CVE?",
                "abstract": "How should a vulnerability case remain traceable when Defender replaces its temporary TVM name with a CVE?",
                "articleBody": "Source facts\nDefender Vulnerability Management can display a zero-day without a CVE under a temporary TVM-XXXX-XXXX name. It replaces that name when a CVE is assigned, while keeping the earlier name searchable in the side panel. When a patch becomes available, the recommendation changes to Update and the zero-day tag is removed. The service displays only zero-days about which it has information. Microsoft Learn.\nApplicability\nUse this continuity check for an already tracked vulnerability whose displayed identifier or label changes. A naming transition and patch availability are lifecycle information; neither is evidence that the organization’s affected installations were repaired.\nDSE recommendation\nKeep the temporary identifier as an alias in the existing vulnerability case when the official CVE becomes available. Ask the case owner to connect earlier mitigation decisions, affected-software evidence and subsequent update work to that same record. Avoid closing the case merely because its old display label disappears, and investigate a possible duplicate before creating another independently tracked item.\nVerification\nSearch for the retained temporary name and compare the resulting record with the assigned CVE and software scope. Record the identifier transition separately from the patch-deployment decision. If an update is now recommended, confirm which affected installations have actually received the approved remediation and which remain exceptions. Keep unverified installations open; the acceptance result is a reconciled case history and observed remediation state, not simply a cleaner zero-day filter.\nOfficial references\nMicrosoft Learn: Zero-day vulnerability handling. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:24:13+00:00",
                "dateModified": "2026-09-10T02:08:04+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-463-preserve-the-link-between-a-temporary-zero-day-name-and-its-later-cve-identifier/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-463-preserve-the-link-between-a-temporary-zero-day-name-and-its-later-cve-identifier/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Preserve the link between a temporary zero-day name and its later CVE identifier"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 240,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Mitigate zero-day vulnerabilities - Microsoft Defender Vulnerability Management | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-zero-day-vulnerabilities"
                }
            }
        ]
    }
}