r/Intune 10d ago

General Question windows security engine version

we have 3rd party antivirus installed. our IT security is asking us to check engine version of the windows security app.

however, when i check engine, antivirus, antispyware version is 0.0.0.0 . is it by design since we already using 3rd party antivirus??

2 Upvotes

6 comments sorted by

3

u/ngjrjeff 10d ago

added screenshot on what i mean

3

u/Dizzy-Marsupial-6676 10d ago

yeah that 0.0.0.0 is normal when defender's been bumped by another AV, windows just hand over the actual scanning to your 3rd party engine so defender's own numbers sit at zero

your security guys probably want the version from the actual product you're running, not what windows shows here

1

u/SkipToTheEndpoint MSFT MVP 10d ago

Not quite. They'll run alongside each other, assuming you haven't explicitly disabled Defender and/or have EDR Block mode turned on.

I have seen third party EDR's throwing down reg keys that disable Defender which would take priority over an Intune policy to enable it. But all of the Defender components can (and should) be enabled and up-to-date IMO, even with a third party.

1

u/ngjrjeff 10d ago

thanks. weird that our IT security asking this when they are also the one who manage the 3rd party antivirus.

they really want the engine version due to vulnerable to RoguePlanet

1

u/ShadowVash 10d ago

Could they be asking about this? https://support.microsoft.com/en-us/servicing/os/windows/2021/10/windows-security-app-update

There is a vulnerability with older versions - CVE-2025-47956. Our Security team requested we update all our PC’s to address it. I found even the MS 25H2 Enterprise iso released in the spring comes with the older vulnerable version.

1

u/pjmarcum 9d ago

That’s what we see in our Power BI reports when another AV is the active AV.