Microsoft Defender for Endpoint is currently experiencing a bug that generates false positive alerts regarding out-of-date versions of the Basic Input/Output System (BIOS) , primarily affecting Dell devices .

The issue, which is being tracked by Microsoft under the ID DZ1163521, is causing security teams to receive notifications to update device firmware when the device is already up to date. This has led to confusion and unnecessary administrative burden for organizations that rely on the endpoint security platform for vulnerability management. Microsoft has confirmed the issue and is actively working to resolve it.
See also: Error in Microsoft Outlook leads to startup failure
The bug specifically affects organizations that use Microsoft Defender for Endpoint to monitor Dell hardware. Affected users and security administrators receive persistent alerts indicating that a device's BIOS is vulnerable and requires an update. However, upon investigation, it is determined that the BIOS version on the device is already the latest available from Dell.
Microsoft Defender for Endpoint: Flood of false alerts
This flood of false alerts creates significant operational challenges, such as alert fatigue among security analysts, who may end up ignoring real threats due to this situation. It also consumes valuable time and resources as IT teams are forced to investigate and validate these non-real issues, distracting them from real security incidents.
See also: New Agent Mode: Microsoft introduces 'vibe working' in Excel & Word

Microsoft has investigated the incident and has identified the root cause of the issue as a code error in the Defender for Endpoint service. According to their update, the flaw lies in the specific logic responsible for retrieving and evaluating vulnerability information related to Dell devices. This faulty code incorrectly interprets BIOS version data from endpoints, leading to incorrect identification of updated systems as vulnerable.
The issue highlights the complexity of properly managing specific firmware and vendor software versions across a wide range of hardware within a centralized security monitoring solution. The issue is not a vulnerability in Dell's BIOS itself, but rather a processing error in Microsoft's security platform.
In an update released on October 2, 2025, Microsoft confirmed that its engineering team has successfully deployed a fix to address the code error. While the issue status remains “OPEN,” the company is now preparing to deploy the patch to the affected environment. Microsoft has stated that it expects the deployment to begin around the time of its next scheduled update.
See also: Microsoft's new Security Store offers cybersecurity solutions

Organizations affected by this bug are urged to monitor Microsoft's service health dashboard for advisory DZ1163521for the latest information on the deployment of the fix. Until the patch is fully deployed, administrators should manually verify the BIOS status of the affected Dell devices to distinguish between fake and real threats.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
