CVE Import Wizard

Applies to: Patch My PC Publisher

Overview

The CVE Import Wizard allows you to bulk match Common Vulnerabilities and Exposures (CVEs) against the Patch My PC catalog to quickly determine whether a fix is available, already published, or unavailable. This feature is commonly used when security teams provide a list of CVE IDs (for example from a vulnerability scanner or audit report) that need to be assessed and remediated.

CVE Import Wizard
circle-exclamation

Import a List of CVE IDs

  1. Open the CVE Import Wizard.

  2. Click Browse, and select a .csv or .txt file that contains the CVE IDs you wish to process.

CVE Import Wizard - Browse
circle-info

Note

The Publisher will perform a regex against all columns and rows in the csv/txt file to look for the well known CVE ID format e.g. CVE-2025-34092

  1. Click Process.

After the processing is complete, you will see the list of all CVE IDs detected in the table grouped by the state.

  • Available An update is available within the Patch My PC catalog, but it is not published within your environment yet.

  • Published The update is already published to WSUS/ConfigMgr and is available for deployment.

  • Unavailable No update is published that contains that CVE ID and there is no update in the Patch My PC catalog matching it.

Processed CVE List

Grouping Results

When Group By Products is enabled, the CVE Import Wizard organizes detected CVE IDs by vendor, and indicates the number of vulnerabilities by vendor. This view is makes it easier to understand which products are responsible for the highest number of CVEs and to prioritize remediation.

Grouped Results

Importing Selected Patches

You can either individually select updates that are in an Available state or click the Select All Available button.

Once the desired updates are selected, click Import Selected Patches to publish them immediately. Importing in this context means publishing the selected updates immediately, outside of the normal sync schedule. After clicking this button, a dialog is displayed allowing you to monitor progress in the PatchMyPC.log file.

Import Selected Patches

A confirmation confirms the outcome of the import operation.

Import Successful

The PatchMyPC.log log file indicates that publish on demand was requested.

PatchMyPC.log indicates the publish on demand
circle-exclamation

Reporting on Updates Imported

After updates are imported through the CVE Import Wizard, a report is generated based on the Alerts you have configured. Depending on your alert configuration, you may receive notifications via Microsoft Teams, Slack, Email, or a combination of these.

In the example below, both a Teams webhook notification and an email report were received, confirming the updates that were imported.

CVE Import Wizard Results by Webhook
CVE Import Wizard Results by Email

Last updated

Was this helpful?