GuideInformationCybersecurityIT

Preserve the link between a temporary zero-day name and its later CVE identifier

How should a vulnerability case remain traceable when Defender replaces its temporary TVM name with a CVE?

Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.
DSE visual intelligenceCyber defenseGuide · 2 min read
Executive summary

What you need to know

How should a vulnerability case remain traceable when Defender replaces its temporary TVM name with a CVE?

Potentially affected

Defender Vulnerability Management records for known zero-day vulnerabilities that initially lack an assigned CVE identifier.

DSE recommendation

Keep the temporary identifier as an alias in the existing vulnerability case when the official CVE becomes available.

Source facts

Defender Vulnerability Management can display a zero-day without a CVE under a temporary TVM-XXXX-XXXX name. It replaces that name when a CVE is assigned, while keeping the earlier name searchable in the side panel. When a patch becomes available, the recommendation changes to Update and the zero-day tag is removed. The service displays only zero-days about which it has information. Microsoft Learn.

Applicability

Use this continuity check for an already tracked vulnerability whose displayed identifier or label changes. A naming transition and patch availability are lifecycle information; neither is evidence that the organization’s affected installations were repaired.

DSE recommendation

Keep the temporary identifier as an alias in the existing vulnerability case when the official CVE becomes available. Ask the case owner to connect earlier mitigation decisions, affected-software evidence and subsequent update work to that same record. Avoid closing the case merely because its old display label disappears, and investigate a possible duplicate before creating another independently tracked item.

Verification

Search for the retained temporary name and compare the resulting record with the assigned CVE and software scope. Record the identifier transition separately from the patch-deployment decision. If an update is now recommended, confirm which affected installations have actually received the approved remediation and which remain exceptions. Keep unverified installations open; the acceptance result is a reconciled case history and observed remediation state, not simply a cleaner zero-day filter.

Official references

Microsoft Learn: Zero-day vulnerability handling. Source reviewed September 9, 2026.

Primary reference

Review the official source

Mitigate zero-day vulnerabilities - Microsoft Defender Vulnerability Management | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE