Microsoft Access Database Engine 2016 Redistributable(accessdatabaseengne.exe). It has been noticed during our scan, below binaries have zlib vulnerabilities

Anonymous
2023-11-23T05:22:26+00:00

For one of our deliverables, we have a requirement to add Microsoft Access Database Engine 2016 Redistributable(accessdatabaseengne.exe). It has been noticed during our scan, below binaries have zlib vulnerabilities.  Need to your help whether these vulnerabilities will be mitigated in future releases or vulnerabilities found in these libraries has no impact.

/FILES/Program Files/Common Files/Microsoft Shared/OFFICE16/ACEWSS.DLL
/FILES/Program Files/Common Files/Microsoft Shared/OFFICE16/Mso20win32client.dll

Download Microsoft Access Database Engine 2016 Redistributable from Official Microsoft Download Center

Kindly request to provide your guidance.

Microsoft 365 and Office | Access | For home | Windows

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

2 answers

Sort by: Most helpful
  1. Anonymous
    2023-11-23T05:30:44+00:00

    If you've identified zlib vulnerabilities in the mentioned files (ACEWSS.DLL and Mso20win32client.dll) within the Microsoft Access Database Engine 2016 Redistributable, it's advisable to check Microsoft's official security updates and announcements for any planned fixes or patches. Additionally, you may want to reach out to Microsoft support or security channels for specific guidance on mitigating these vulnerabilities or to inquire about future releases that address these issues. Keeping software up-to-date is a common practice for security, so regularly monitoring for updates from the vendor is crucial.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Tom van Stiphout 40,211 Reputation points MVP Volunteer Moderator
    2023-11-23T16:06:13+00:00

    Right-click each file > properties > digital signatures.

    I only have the first file, and it has a valid signature from MSFT. That tells you two things: the file came from them, and it was not modified. Therefore, you can trust it. Your spam scanner is apparently not very sophisticated, or it would have picked up on that.

    Was this answer helpful?

    0 comments No comments