How can I follow the Security Recomendation to update OpenSSL if we aren't running this on our machines

Ken Colling 0 Reputation points
2024-04-24T16:15:30.6433333+00:00

In Microsoft Defender we have a Security Recommendation to update OpenSSL. We don't currently run OpenSSL so what should we update in order to address this vulnerability

Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,231 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Hania Lian 8,121 Reputation points Microsoft Vendor
    2024-04-25T02:28:04.7533333+00:00

    Hello,

    If Microsoft Defender recommends updating OpenSSL and you determine that your system isn't running OpenSSL, it could be a false positive detection or outdated software inventory. Here are some things you can do to fix this issue:

    Validation checklist: Double-check your system's software checklist to confirm that OpenSSL is not installed. Sometimes, an application may bundle OpenSSL without being explicitly installed.

    Scan for vulnerabilities: Use Microsoft Defender's vulnerability management capabilities to scan your system for specific vulnerabilities that are mentioned.

    https://techcommunity.microsoft.com/t5/microsoft-defender-vulnerability/reduce-openssl-3-0-vulnerabilities-risks-with-microsoft-defender/ba-p/3668567

    Check if there are any Windows updates, and if so, update the system to the latest.

    Best Regards,

    Hania Lian

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments