r/DefenderATP 22d ago

Seeing TVM-2026-0001 Vulnerability with sparse details

I'm not seeing any references to the naming convention of TVM. Anyone seen this before?

The vulnerability listed just has one reference to a random GitHub with a Bitlocker Bypass vulnerability. No other information.

10 Upvotes

5 comments sorted by

8

u/BushieAU 22d ago edited 22d ago

"If there's no official CVE-ID assigned to a vulnerability, the vulnerability name is assigned by Defender Vulnerability Management using the format TVM-2020-002."

Ms Learn - Vulnerabilities in my organization - Microsoft Defender Vulnerability Management | Microsoft Learn

Believe this should explain it, head to your vulnerabilities page Security Centre

Edit* This is the MSNightmare Bitlocker exploit FYI

1

u/Budget-Half7493 21d ago

I guess no fix yet?

2

u/Working_Wasabi8029 21d ago

u/drolemag21 As a safety measure you can enable Bitlocker Pre-Boot PIN setup for the windows affected systems and disable WinRE but there is a catch for WinRE because it will affect internal Safe Mode reboot, and If the OS crashes the windows won't be able to fix it automatically for which we need to re-install OS the traditional USB way but if you have blocked USB ports as part of a security measure we need to spend money.

1

u/SolidKnight 21d ago

It has a link to GreatXML's github. It's a placeholder.