Forum Discussion
hbrooks2375
Nov 14, 2023Copper Contributor
OpenSSL
We have the recommendation to update OpenSSL. However, we can not figure out how to actually do this. There seems to be no installed location of OpenSSL so how can we update this? I have found a few ...
MikeP751860
Mar 06, 2024Brass Contributor
fatherosam_1 - The February version of Power BI Desktop has updated the OpenSSL from 3.0.9 to 3.0.11 but that is still vulnerable. The latest secure version is 3.0.13.
Have you reported the Microsoft applications to MSRC? I was able to get them to accept a report for CURL last year but they didn't accept for Power BI when I tried.
fatherosam_1
Mar 06, 2024Copper Contributor
Not yet - I have raised it more generally.
And so far I'm on my third hand off (not our area I'll pass you onto ...)
with MS Support
I have found vulnerable editions in system32 drivers, onedrive sync libraries and office ODBC, along with Power bi and others
I'll just keep answering questions until someone finally takes it on