Share via

Defender Vulnerability Management still shows OpenSSL CVEs after application update

Abdallah Jaber 5 Reputation points
2026-02-05T20:06:46.4033333+00:00

Microsoft Defender for Endpoint Vulnerability Management is still reporting OpenSSL 3.x CVEs for libssl-3-x64.dll and libcrypto-3-x64.dll on a device. The application containing these DLLs has been updated, and the file versions on disk have changed. Is there a known delay or required device action for Defender for Endpoint to refresh software inventory and vulnerability assessment after third-party application updates, or should the CVEs clear automatically within a specific timeframe?

Microsoft Security | Microsoft Defender | Microsoft Defender for Identity
{count} vote

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.