This is the Trace Id: 5ecc242f711f5976822da47ff9d606b2
Skip to main content
MSRC

Definition of a Security Vulnerability

As a CVE Naming Authority (CNA), Microsoft follows the MITRE.org definition of a security vulnerability which defines a security vulnerability as โ€œa weakness in the computational logic (e.g., code) found in software and hardware components that, when exploited, results in a negative impact to confidentiality, integrity, OR availability. Mitigation of the vulnerabilities in this context typically involves coding changes but could also include specification changes or even specification deprecations (e.g., removal of affected protocols or functionality in their entirety).โ€ MITRE.org CNA Rulesย  7.1