A cloud-native solution that protects workloads across hybrid and multi-cloud environments with threat detection and security recommendations
Hi Everyone,
As per my testing and research, I think this will be an ongoing vulnerability recommendation.
For example, Zoom addressed the vulnerability with OpenSSL 3.1.4 back in Jan 2024, screen capture below https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0068823
But, Microsoft reported the CVE-2024-2511 which says that multiple versions of OpenSSL still are impacted:
After some testing, I uninstalled Zoom and found that the vulnerability was gone, but Defender detected it again as Zoom as I reinstalled the latest version.
I did find the OpenSSL Recommendation helpful because there were apps and left over files that users in my organization where not using and were increasing the impact of this vulnerability, removing those specifics apps and files make the list shorter.
Hope my findings help you all.