Protection against phishing, malware, and other threats targeting email and collaboration tools in Microsoft 365
Open SSL Vulnerability libcrypto-3-x64.dll and libssl-3-x64.dll
Experiencing issues with OpenSSL vulnerabilities affecting organization security score. So far, I was not
able to find any fix for it, tried updating the programs, doing windows updates even take ownership of the program file and delete manually. but the files return after the system updates.
Is there any fix for this?
Microsoft Security | Microsoft Defender | Microsoft Defender for Office 365
-
Rukmini • 43,915 Reputation points • Microsoft External Staff • Moderator
2026-03-18T21:54:47.6133333+00:00 Hey Alex, it looks like your vulnerability scanner is flagging the OpenSSL DLLs that ship inside Windows “Inbox”/Store apps (OneDrive, Paint, Photos, etc.). Manually deleting those DLLs won’t stick because Windows reprovisions them on the next OS or app update. Here’s what you can do:
- Update Microsoft Defender/Vulnerability Management definitions • Microsoft has fixed the false-positive reporting of OpenSSL in inbox apps (CVE-2024-12797). • Make sure Defender Antivirus (and Defender for Endpoint, if deployed) is on the latest security intelligence. • Restart a scan once definitions are current—you should no longer see libcrypto-3-x64.dll or libssl-3-x64.dll flagged.
- Update the Store apps themselves • Open Microsoft Store (or use winget) and install any updates for OneDrive, Paint, Photos, etc. • These updated packages include patched OpenSSL libraries, so the DLL versions get bumped and the CVEs go away.
- Keep Windows OS patched • Run Windows Update to ensure your builds include the latest inbox-app fixes. • You can also check the Windows release health page for any app-related advisories on your OS version.
- If you still see reports after updating • Use the “Report inaccuracy” link on the component page in Defender for Cloud or your scanner to flag a false positive. • Optionally review “Modern apps or application packages are reported as vulnerable due to multiple versions” in case an old side-by-side version still lives on disk.
Hope that clears it up—deleting the DLLs by hand won’t help long term, but keeping Defender defs and your Store apps fully updated will.
Reference list
- Microsoft Defender Antivirus security intelligence and product updates https://learn.microsoft.com/defender-endpoint/microsoft-defender-antivirus-updates#how-to-install-an-update
- Windows release health https://learn.microsoft.com/windows/release-health/
Note: This content was drafted with the help of an AI system. Please verify the information before relying on it for decision-making.
-
Rukmini • 43,915 Reputation points • Microsoft External Staff • Moderator
2026-03-19T20:47:20.4966667+00:00 Hello alex kalapnauth
Following up to see if the above provided information was helpful. If you have any further queries do let us know.
-
Kumar Phanindra Yelchuri • 15 Reputation points
2026-03-28T10:53:16.93+00:00 Rukmini - We are observing OpenSSL vulnerabilities reported on systems where Microsoft Store apps such as OneDrive, Paint, and Photos are installed.
- All Microsoft Store apps are updated to their latest versions
- Windows OS is fully patched and up to date
- Despite this, vulnerability scans continue to flag outdated OpenSSL components associated with these apps
It appears that the OpenSSL libraries bundled within these Store apps are not being updated or remediated through normal update channels.
Questions:
- How are OpenSSL dependencies within Microsoft Store apps managed and patched?
- Is there a recommended approach to remediate or suppress these vulnerabilities?
- Is Microsoft planning a fix or update for these components, and is there any ETA?
Any clarification or official guidance would be appreciated.
-
Martin Thurgate • 15 Reputation points
2026-04-01T05:52:41.82+00:00 Hi Rukmini - I'm seeing this issue across my entire customer base (we're an MSP). Was this only very recently resolved by Microsoft do you know? I have tried your approach above on my own system and will report back shortly on whether it worked.
-
Kumar Phanindra Yelchuri • 15 Reputation points
2026-04-03T18:58:45.6966667+00:00 Any update on this?
-
Martin Thurgate • 15 Reputation points
2026-04-06T22:17:03.9033333+00:00 Similar to Kumar, I can confirm that the steps above did not work for me. I've been into the App Store and checked for updates. All new updates have been installed. I've run Windows Update manually and confirmed there are no new Windows updates that need to be installed. However, my device continues to appear in Defender as vulnerable, showing OpenSSL issues across numerous Microsoft applications. We can use the Report Inaccuracy button, but having thousands of devices under management across hundreds of customers, I'd infinitely prefer Microsoft fixes this issue.
-
-
Mack Swift • 5 Reputation points
2026-04-30T00:51:38.3166667+00:00 Is there any update on this? These vulnerable OpenSSL libraries in Paint, Photos, and OneDrive are causing serious issues for Security Teams. We can't keep explaining to C-suite that it's Microsoft's issue to fix. They look to us to take care of that, and you're making us look like fools.
The fact that Microsoft keeps distributing apps with OpenSSL libraries with serious CVEs that their own Defender platform flags as a problem is embarrassing.
This either needs to be fixed yesterday or you provide a way for us to distribute and patch these libraries with the latest 3.6.2 version ourselves. I've tried multiple ways to update them in the windowsapps directory, but no dice. Only deleting the files works (and that's not a solution).
-
Pickering, Billy • 0 Reputation points
2026-05-26T12:50:28.49+00:00 Not only is it being flagged for paint, one drive, and Photos but also with Guest Configuration for Windows, and Microsoft Office Hub. All app store entries.
-
Adam Parsons • 0 Reputation points
2026-06-17T11:05:17.8566667+00:00 Any update, we are seeing this flagged in Defender Portal across multiple products, vendors don't seem bothered or say it's patched in x version but defender still flagging. Is this a false positive?
-
Martin Thurgate • 15 Reputation points
2026-06-17T23:13:09.09+00:00 Hey Adam, I had my team investigate this and I can confirm that it's not a false positive. These applications are using vulnerable OpenSSL libraries. The issue is Microsoft (and other vendors to be fair) don't appear to be in any hurry to patch these applications.
-
xeroday • 0 Reputation points
2026-09-01T06:17:23.52+00:00 Hi, any update to this? Endpoint Central has picked up 3 days ago:
C:\Program Files\Microsoft OneDrive\26.145.0728.0011\libcrypto-3-x64.dll (2 out of 6 computers)
C:\SWSetup\intel_security_engine_software_ME_2618.9.30.0\Drivers\ICLS\lib\libcrypto-3-x64.dll
I checked the other ones without CVE. And libcrypto-3-x64.dll does not exist. Only FileCoAuthLib64.dll and FileSyncShell64.dll
Is it safe to delete C:\Program Files\Microsoft OneDrive\26.145.0728.0011\libcrypto-3-x64.dll ?
Thanks
Sign in to comment