Share via

OpenSSL vulnerabilities showing in Defender Dashboard

Jeff Thorne 50 Reputation points
22 Sept 2023, 20:14

We have multiple devices showing up with OpenSSL vulnerabilities. It is detecting two dll files that it is flagging. Which they are libssl-3-x64.dll and libcrypto-3-x64.dll. It is flagging this for multiple different applications through out multiple devices. Some devices it's not the same application. Is defender showing a false negative of these vulnerabilities. If this are not false negatives then what is the process to update the dll files inside the applications?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,411 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
210 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
149 questions
{count} votes

10 answers

Sort by: Newest
  1. Stephen Holder 0 Reputation points
    03 Oct 2024, 11:34

    There is a similar issue with AutoDesk DWG Trueview (ADODIS).

    c:\program files\autodesk\adodis\v1\setup\cer\libcrypto-3-x64.dll (v3.0.13) generates a notification within the Defender Portal.

    I have upgraded to Trueview 2025, and this has updated the above dll to v3.0.14. I don't know if this will resolve the OpenSSL warning in Defender though.

    0 comments No comments

  2. Gary I 5 Reputation points
    06 Sept 2024, 02:17

    I have been researching this again today (having had this issue for months) and found the following: OpenSSL are aware of the issues that are raised in CVE-2024-2511 but consider it low severity and won't be addressing it anytime soon:

    This issue only affects TLS servers supporting TLSv1.3. It does not affect TLS
    clients.
    
    The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL
    1.0.2 is also not affected by this issue.
    
    OpenSSL 3.2, 3.1, 3.0, 1.1.1 are vulnerable to this issue.
    
    OpenSSL 3.2 users should upgrade to OpenSSL 3.2.2 once it is released.
    
    OpenSSL 3.1 users should upgrade to OpenSSL 3.1.6 once it is released.
    
    OpenSSL 3.0 users should upgrade to OpenSSL 3.0.14 once it is released.
    
    OpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1y once it is released
    (premium support customers only).
    
    Due to the low severity of this issue we are not issuing new releases of
    OpenSSL at this time. The fix will be included in the next releases when they
    become available. The fix is also available in commit e9d7083e (for 3.2),
    commit 7e4d731b (for 3.1) and commit b52867a9 (for 3.0) in the OpenSSL git
    repository. It is available to premium support customers in commit
    5f8d2577 (for 1.1.1).
    
    

    Source: https://openssl-library.org/news/secadv/20240408.txt

    This was dated 8 April 2024.

    It doesn't matter what Zoom or PowerBI or anyone do, CVE-2024-2511 will be around until OpenSSL address the weaknesses in those specific libraries.

    If you have Zoom, update to version 6.1.0 or above to address OpenSSL flaws except CVE-2024-2511 and CVE-2024-4603, which doesn't affect clients:

    User's image

    Source: https://devforum.zoom.us/t/zoom-5-6-10-vulnerabilities-with-openssl-dll-need-version-3-1-5/98806/78?page=4

    1 person found this answer helpful.
    0 comments No comments

  3. Ronald Bok 0 Reputation points
    11 Jun 2024, 07:57

    I Got the same Issue. Strange thing it is on Onedrive I'm Not sure what the lastest version of ondrive is, becourse the version list on the Microsoft site is not up to date. But the Warning is on all version of onedrive. Here are some Exampels.

    c:\program files\microsoft onedrive\24.101.0519.0010\libcrypto-3-x64.dll

    c:\program files\microsoft onedrive\24.108.0528.0005\libcrypto-3-x64.dll

    c:\program files\microsoft onedrive\24.101.0519.0010\libssl-3-x64.dll

    c:\program files\microsoft onedrive\24.108.0528.0005\libssl-3-x64.dll


  4. Julio Soza 5 Reputation points
    18 Apr 2024, 14:51

    Hi Everyone,

    As per my testing and research, I think this will be an ongoing vulnerability recommendation.

    For example, Zoom addressed the vulnerability with OpenSSL 3.1.4 back in Jan 2024, screen capture below https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0068823User's image

    But, Microsoft reported the CVE-2024-2511 which says that multiple versions of OpenSSL still are impacted:

    User's image

    After some testing, I uninstalled Zoom and found that the vulnerability was gone, but Defender detected it again as Zoom as I reinstalled the latest version.

    I did find the OpenSSL Recommendation helpful because there were apps and left over files that users in my organization where not using and were increasing the impact of this vulnerability, removing those specifics apps and files make the list shorter.

    Hope my findings help you all.

    1 person found this answer helpful.
    0 comments No comments

  5. Brock 0 Reputation points
    03 Apr 2024, 21:29

    We're experiencing the same issue on our domain. Lots of these are in driver folders, updated in the last six months.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.