OpenSSL Vulnerability Shown on Microsoft Defender for Cloud Dashboard - OneDrive affected app
An OpenSSL vulnerability has been flagged on one of our devices by Microsoft Defender for Cloud.
The vulnerability has listed two dll files as the main culprits (both installed via OneDrive):
- libcrypto-3-x64.dll
- libssl-3-x64.dll
The OneDrive version is the latest, as far as I know (24.196.0929.0005), and was updated on 26-Oct-2024.
However, it appears that the dll file versions have persisted at 3.3.0.0, which is considered vulnerable by Microsoft Defender's vulnerability scanner.
Therefore, how do we address this vulnerability if it cannot be addressed via a OneDrive update, as seems to be the case here?
Microsoft Defender for Cloud
-
Bill Shannon • 10 Reputation points
2024-11-12T16:55:16.8766667+00:00 This is a headache for me as well, especially when the older OneDrive versions are still hanging around. Even taking ownership and Full Control of the files (in the older directories) won't let me delete them. And security folks like me don't like this old vulnerable stuff hanging around. Yet, OneDrive's update mechanism for some reason won't remove older versions.
-
Champ • 1 Reputation point
2024-11-14T03:05:42.6633333+00:00 Hi everyone,
Did you managed to find a solution for this? It is flagging as a possible attack path by defender but not sure what to do with this.
-
Pauline Mbabu • 595 Reputation points • Microsoft Employee
2024-11-25T10:32:05.7566667+00:00 Hello @Eric Wasike ,
The relevant Product Team is working to have this fixed.
-
Mike-H • 45 Reputation points
2024-11-26T18:05:59.0966667+00:00 @Pauline Mbabu please can you confirm if the fix being worked on is to resolve this being flagged as a false positive or if we await a version update to One Drive which will resolve the issue?
-
Alcebíades Pardal Grandizoli • 5 Reputation points
2024-12-09T07:02:33.14+00:00 @Pauline Mbabu Any news?
-
Zachery Paul Gardner • 0 Reputation points
2024-12-19T17:45:49.0266667+00:00 We are also having this issue. Is there a patched version of OneDrive available? This seems to have persisted through the last several updates and we are not getting any answers on timelines for correction.
-
OZTEZCAN Batuhan • 10 Reputation points
2025-01-03T07:18:37.5933333+00:00 This issue still persists in the latest production build.: 24.226.1110.0004. I wonder when it will be patched.
-
WesMadden • 6 Reputation points
2025-01-03T23:26:45.1933333+00:00 OpenSSL component vulnerabilities in Defender Vulnerability Management seem too heavily weighted against the exposure score. We are showing several Microsoft products with vulnerable OpenSSL components with the biggest being OneDrive. This seems like it will be a constant issue going forward so I would recommend that Microsoft take a look at how heavily weighted this is against the exposure score otherwise the exposure score doesn't seem to be an accurate construct.
-
SM • 20 Reputation points
2025-01-08T15:44:32.1866667+00:00 Any news on the release date for an updated version please?
Thanks,
SM -
Pauline Mbabu • 595 Reputation points • Microsoft Employee
2025-01-23T04:05:01.6066667+00:00 Apologies for getting back to you late.
OpenSSL detections are actual risks, and most Microsoft products, including OneDrive, are in the process of being updated. I am not able to confirm the exact day that the update will be released but this is being investigated. Please be patient with us as we work on making the necessary updates. -
Martin L. Mogensen • 20 Reputation points
2025-01-27T08:02:50.5+00:00 Dear Pauline Mbabu,
I think a lot of us already have been more than patience. This thread started almost 3 month ago... the file mentioned is version 3.3.0, but it was superseded by version 3.3.1 which was released 4th june 2024 (7.5 month ago), and later on by version 3.3.2 was released September 3rd 2024 (4.5 month ago).
I can't help thinking that Microsoft doesn't prioritize security, since updating applications is prioritized that low.
Is is naive to hope that you can get this escalated to someone, who can ensure this is being fixed, instead of postponed and excused?
I do know that you are not the one to blame, so please take this personal.
-
SM • 20 Reputation points
2025-01-27T09:11:55.6966667+00:00 Thanks for coming back to us Pauline, it is appreciated.
If you have a route to make suggestions within Microsoft, could it be fed upward please to ask that any Microsoft product that includes open source libraries like OpenSSL, Log4J etc, always release the latest stable version of that library when they are updated?
The history shows that it's only a matter of time before CVEs are published for the older or current version of these libraries so it would at least hopefully improve the situation over time and re-assure customers like ourselves that we only need wait for the next release for the issue to be resolved.
Thanks again,
SM -
SM • 20 Reputation points
2025-01-27T14:39:53.6733333+00:00 On our estate, we've seen that version 25.* is now being pushed out which contains openSSL 3.4. More importantly, that currently has no CVEs in Defender which is brill. Thanks 😊
Sign in to comment