Microsoft Defender for Endpoint Bug Triggers Numerous False BIOS Alerts
Microsoft has identified a bug in its Defender for Endpoint service, which is causing false positive alerts related to outdated Basic Input/Output System (BIOS) versions on Dell devices. This issue, tracked under reference ID DZ1163521, prompts…
Microsoft has identified a bug in its Defender for Endpoint service, which is causing false positive alerts related to outdated Basic Input/Output System (BIOS) versions on Dell devices. This issue, tracked under reference ID DZ1163521, prompts unnecessary firmware update notifications despite the BIOS being current.
This situation creates confusion and additional administrative overhead for organizations utilizing the endpoint security platform for vulnerability management. Microsoft has acknowledged the issue and is actively working on a resolution.
The bug affects users of Microsoft Defender for Endpoint monitoring Dell hardware, where alerts incorrectly indicate that a device’s BIOS is vulnerable and needs updating. Upon investigation, it is confirmed that the BIOS version is up-to-date.
Microsoft has traced the problem to a code bug in the service's logic responsible for fetching and evaluating vulnerability data. This leads to misinterpretation of BIOS version data, resulting in improper alerts.
This issue, tracked under reference ID DZ1163521, prompts unnecessary firmware update notifications despite the BIOS being current.
The erroneous alerts contribute to operational challenges, including alert fatigue among security analysts and diversion of resources to verify and address these alerts. This impacts the ability to focus on genuine security threats.
On October 2, 2025, Microsoft announced a fix has been developed for the issue. While the status remains "OPEN," deployment of the corrective patch is planned for the next scheduled update. Organizations are advised to monitor the Microsoft service health dashboard for updates on the fix rollout.
Until the patch is deployed, administrators must manually verify the BIOS status of flagged Dell devices to distinguish between false positives and legitimate vulnerabilities.
For more information, organizations can refer to advisory DZ1163521 on the Microsoft service health dashboard.
Based on reporting by Cyber Security News.
