Event details
Unanswered question from September 17th:
We are seeing an increasing number of vulnerability findings in Microsoft applications where the application itself appears current, but a bundled third-party security library remains vulnerable.
As a specific example, Microsoft Defender Vulnerability Management is reporting that Microsoft OneDrive version 26.153.0809.0004 contains OpenSSL 3.4.5. At the time of assessment, OpenSSL 3.4.6 had been available since 9 June 2026 and OpenSSL 3.4.7 since 25 August 2026, meaning OneDrive appears to have missed at least one complete OpenSSL security release cycle and remained on a vulnerable OpenSSL version for more than three months after a fixed upstream release became available.
From an enterprise vulnerability management perspective, this raises several questions:
- What is Microsoft's expected servicing timeframe for critical third-party components embedded within Microsoft applications such as OneDrive?
- When a current Microsoft application is flagged by Microsoft Defender Vulnerability Management due to a vulnerable bundled library, should customers treat that vulnerability as a remediation requirement, or as a risk that must be accepted until Microsoft republishes the application?
- Is there a documented service level objective, target timeframe, or best-practice guidance for how quickly Microsoft applications should incorporate upstream security fixes for bundled libraries such as OpenSSL?
- What is Microsoft's recommended course of action when no newer Microsoft-published version is available but vulnerability scanners continue to report critical or high-severity findings within Microsoft-managed software?
We are looking for guidance on how enterprise security teams should assess, report, and respond to these findings, particularly when the vulnerable component is embedded within a Microsoft application and remediation is wholly dependent on Microsoft's release process.
- GLComputingOct 07, 2026Brass Contributor
Hi stdcsb - I've been working with MS support on this issue for several months.
Not just OpenSSL, but a few other third-party apps installed with MS apps that are flagged as vulnerable, with the recommendation to get updates from the vendor (kinda useless when MS is the vendor).
While the problem versions weren't exploitable, I had to argue that it wasted many hours to realise the Defender recommendation could be ignored. This is even more complex when Defender XDR and Defender for Cloud give conflicting recommendations.When I pushed the issue as a way to reduce MS support costs (especially since many of the support guys I dealt with at first didn't understand the system), they finally acknowledged it was worth escalating to the Security Exposure Management team.
While they can't confirm a time frame, I felt good that they appreciate the need to adjust recommendations for components installed with MS apps.In the meantime, the only workaround is to exclude suggestions for components in MS apps and check them every month or so.
Regards, Mike