Vulnerability management for Linux now generally available
Published Jun 29 2021 06:20 AM 22.2K Views
Microsoft

In May we announced the support for Linux across our threat and vulnerability management capabilities in Microsoft Defender for Endpoint. Today, we are excited to announce that threat and vulnerability management for Linux is now generally available across Red Hat, Ubuntu, CentOS, SUSE, and Oracle, with support for Debian coming soon. In addition to Linux, the threat and vulnerability management capabilities already support macOS and Windows, with support for Android and iOS coming later this summer to further expand our support of third party platforms.   

 

Vulnerability Management plays a crucial role in monitoring an organization’s overall security posture. That’s why we continue to expand our cross-platform support to equip security teams with real-time insights into risk with continuous vulnerability discovery, intelligent prioritization, and the ability to seamlessly remediate vulnerabilities for all their platforms. With the general availability of support for Linux, organizations can now review vulnerabilities within installed apps across the Linux OS and issue remediation tasks for affected .

 

Image 1: Software inventory page in the vulnerability management console, showing various Linux platformsImage 1: Software inventory page in the vulnerability management console, showing various Linux platforms

 

 

Image 2: Software inventory page in the vulnerability management portal, showing glibc across various Linux systemsImage 2: Software inventory page in the vulnerability management portal, showing glibc across various Linux systems

 

Support for the various Linux platforms in threat and vulnerability management closely follows what is available across our Endpoint Detection and Response (EDR) capabilities. This alignment ensures a consistent experience for Microsoft Defender for Endpoint customers, as we continue to expand our cross-platform support.

 

More information and feedback

The threat and vulnerability management capabilities are part of Microsoft Defender for Endpoint and enable organizations to effectively identify, assess, and remediate endpoint weaknesses to reduce organizational risk.

 

Check out our documentation for a complete overview of supported operating systems and platforms.

 

We want to hear from you! If you have any suggestions, questions, or comments, please visit us on our Tech Community page.

 

6 Comments
Microsoft

this capability rocks. Nice work team.

Brass Contributor

The MS Defender for Endpoint will check others apps like Adobe Acrobat, Winzip, Google Chrome and etc as Comodo One or Acronis Advanced Management does? Including hardware/software inventory?

Brass Contributor

@Renato Pereira : MS Defender for Endpoint (Windows version) certainly does, we get flags for new vulnerabilities in Google Chrome usually a couple of times a month, plus have had flags for Zoom, Foxit Reader, Mozilla Firefox, Zscaler Client Connector, Intel Proset Wireless etc. Not sure if there is an exact list of what apps are checked available, and whether the Linux version also does third-party app checks?

Brass Contributor

Hi @Steve Burkett,

 

Do you know if it just check new updates or also perform the update itself for the application??

Brass Contributor

It's just flagging if there are published CVE's against the app, to warn you that you should update (if a new version is available yet!), it doesn't do that update for you though. You'd use something like Microsoft Endpoint Manager (aka Intune & SCCM) to roll out your updates.

 

Brass Contributor

hum...

I didn't know that INTUNE could handle with software updates

Version history
Last update:
‎Jun 24 2021 03:09 PM
Updated by: