Introduction
The vulnerability scanner, a feature of Scam, phishing, and malware protection for Windows, automatically scans your apps for weaknesses. It notifies you of any known security flaws, allowing you to update the vulnerable software and protect your device from attacks.
How does the vulnerability scanner work?
- Automated app scanning – Automatically scans software installed on your Windows device to detect known security flaws and weaknesses that could be exploited.
- Instant vulnerability alerts – Immediately notifies you when a vulnerability is found, so you know exactly which application needs to be updated. Each detected vulnerability is labeled with a severity badge - LOW, MEDIUM, HIGH, or CRITICAL LEVEL VULNERABILITY - so you can prioritize which apps to update first.
- Proactive attack prevention – Helps you minimize risk by allowing you to patch security holes before cybercriminals have a chance to exploit them.
- Effortless protection – Runs automatically in the background 24/7, providing an extra layer of device security without requiring any manual action from you.
Requirements
Make sure you have the NordVPN Plus or Ultimate subscription and that the NordVPN application is installed on your Windows device.
Here's what to do
- Open the NordVPN app.
- Click the shield icon on the left side of the NordVPN application to open the Scam, phishing, and malware protection tab.
- Open Advanced settings (the "Protection preferences" card).
- In the Anti-malware section, enable the Vulnerability scanner by clicking the toggle.
Reviewing detected vulnerabilities
When the vulnerability scanner detects a vulnerable app on your device, you will see a "Security issues found" banner at the top of the Scam, phishing, and malware protection main page, with a counter showing how many issues require action and a Review and resolve button. Clicking it opens Protection history with the All threats tab selected, where vulnerable apps are listed alongside other detected threats.
To inspect a specific vulnerable app, click its row and select Manage threat. A modal will open showing:
- The app name and the vulnerable version.
- A severity badge - LOW, MEDIUM, HIGH, or CRITICAL LEVEL VULNERABILITY - indicating how serious the detected issue is.
- A Recommended actions section with guidance on how to resolve the vulnerability (typically, updating the affected app to its latest version).
The vulnerable app entry is removed from Protection history automatically once the vulnerability is resolved (for example, after you update the affected app).
Additional tips
- Only download and install software from official and trusted developer websites.
- Treat the Security issues found banner on the main page as a priority - it appears only when threats (quarantined files or vulnerable apps) require your attention, and the counter updates immediately after each issue is resolved.
- Prioritize CRITICAL LEVEL VULNERABILITY entries first, then HIGH, then MEDIUM, then LOW.