(Provider_Name:Microsoft\-Windows\-Audit\-CVE OR Provider_Name:Audit\-CVE) EventID:1