Patch Policy
How fast we fix known vulnerabilities, and how we decide.
Timelines
Severity follows the Common Vulnerability Scoring System, adjusted for whether the component is actually reachable in our deployment. A critical score in a library we do not call is not a critical risk, and we document that reasoning rather than ignoring the finding.
| Severity | CVSS | Remediation target |
|---|---|---|
| Critical | 9.0 to 10.0 | 7 calendar days |
| High | 7.0 to 8.9 | 30 calendar days |
| Medium | 4.0 to 6.9 | 90 calendar days |
| Low | 0.1 to 3.9 | Next scheduled maintenance |
Scope
- Application dependencies and runtime packages
- Container and virtual machine images we build
- Configuration of the managed Azure services we operate
Patching of the underlying Azure platform is Microsoft's responsibility under the shared responsibility model.
Emergency changes
A vulnerability under active exploitation is patched as fast as a safe deployment allows, without waiting for a maintenance window. Customers are notified if the change affects availability.
Exceptions
Where a fix cannot be applied within target, the exception is recorded with the reason, the compensating control, and a review date. Exceptions are time-limited.