# Investigate a Defender software-version mismatch before calling it an inventory error

> Can Defender legitimately display a software version that differs from the locally installed version string?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-337-investigate-a-defender-software-version-mismatch-before-calling-it-an-inventory/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:19+00:00
- Modified: 2026-09-10T01:40:03+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Can Defender legitimately display a software version that differs from the locally installed version string?

## Potentially affected

Software version records in Microsoft Defender Vulnerability Management inventory.

## DSE recommendation

Preserve the installed and displayed version strings and reconcile the underlying software evidence before reporting an inaccuracy.

## Article

## Source facts

Defender Vulnerability Management intentionally normalizes versions for some software to improve cross-device correlation and assessment. Consequently, its displayed string can differ from the installed string without representing a different functional version. Microsoft does not describe every difference as an error. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-software-inventory).

The device’s Software Evidence section identifies detection evidence in the registry, on disk or both. The inventory overview refreshes every three to four hours and cannot be manually forced to synchronize. Report inaccuracy provides a route for an actual incorrect software detail or device count. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-software-inventory).

## Applicability

Review software version records in Microsoft Defender Vulnerability Management inventory. This brief concerns reconciliation of an observed version discrepancy, not a claim that every software product is assessed or that all differing strings are equivalent.

## DSE recommendation

DSE recommends preserving the locally observed version, displayed version, product identity and observation time together. Inspect the device-level evidence before proposing a reinstall or reporting a false vulnerability result. Where normalization does not explain the discrepancy, collect the specific evidence needed for an inaccuracy report. Do not invent a conversion formula from one documented product example and apply it to unrelated software.

## Verification

Compare a known installation with its registry or disk evidence and the portal record after the documented refresh interval. Confirm that the same product and device are being compared. Record whether normalization, delayed inventory or an unresolved discrepancy best fits the evidence, without presenting an inference as a confirmed correction. Preserve both original strings in the final review.

## Official references

[Microsoft Learn: Software inventory](https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-software-inventory).

## Primary reference

- Name: Software inventory - Microsoft Defender Vulnerability Management | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-software-inventory
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Investigate a Defender software-version mismatch before calling it an inventory error,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-337-investigate-a-defender-software-version-mismatch-before-calling-it-an-inventory/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
