Microsoft Security Response Center has been scoring Windows and Browser vulnerabilities since 2016. Now we are scoring every vulnerability and displaying the details that make up that score in the new version of the Security Update Guide. This is a precise method that describes the vulnerability with attributes such as the attack vector, the complexity of the attack, whether an adversary needs certain privileges, etc. You can use the score to assess the risk of the vulnerability. For example, if the scope is Changed, it means that the exploit can start in one place, say application memory, and jump to another place like the kernel memory, the score would move from 5 to 6.5.”]