MSRC

Microsoft Security Response Center

Microsoft-Sicherheitsreaktionszentrum

The MSRC is the central body at Microsoft for handling and publishing security vulnerabilities in Microsoft products. It coordinates the response to reported vulnerabilities, assigns its own Common Vulnerabilities and Exposures (CVE)-IDs as a CVE Numbering Authority (CNA) and publishes the monthly cumulative updates. Given the prevalence of Microsoft software, it is one of the most consequential vendor bodies of all.

History & facts. The MSRC is an example of a large, established Product Security Incident Response Team (PSIRT) — a vendor body for product security. It receives vulnerability reports, coordinates remediation and traditionally bundles fixes in the monthly update rhythm, the industry-established „Patch Tuesday“. The advisories are available machine-readable and thus integrate well into automated processes.

Outlook & recommendation. Because of the market penetration of Microsoft products, MSRC publications co-determine the patch rhythm of many organisations. It is sensible not to work through the monthly updates wholesale but to prioritise by real exposure — that is, to draw on Common Vulnerability Scoring System (CVSS) and Exploit Prediction Scoring System (EPSS) as well as the Known Exploited Vulnerabilities Catalog (KEV) status rather than patching blindly by severity.

MSRC — Microsoft Security Response Center