Event details
We are seeing an increasing number of vulnerability findings in Microsoft applications where the application itself appears current, but a bundled third-party security library remains vulnerable.
As a specific example, Microsoft Defender Vulnerability Management is reporting that Microsoft OneDrive version 26.153.0809.0004 contains OpenSSL 3.4.5. At the time of assessment, OpenSSL 3.4.6 had been available since 9 June 2026 and OpenSSL 3.4.7 since 25 August 2026, meaning OneDrive appears to have missed at least one complete OpenSSL security release cycle and remained on a vulnerable OpenSSL version for more than three months after a fixed upstream release became available.
From an enterprise vulnerability management perspective, this raises several questions:
- What is Microsoft's expected servicing timeframe for critical third-party components embedded within Microsoft applications such as OneDrive?
- When a current Microsoft application is flagged by Microsoft Defender Vulnerability Management due to a vulnerable bundled library, should customers treat that vulnerability as a remediation requirement, or as a risk that must be accepted until Microsoft republishes the application?
- Is there a documented service level objective, target timeframe, or best-practice guidance for how quickly Microsoft applications should incorporate upstream security fixes for bundled libraries such as OpenSSL?
- What is Microsoft's recommended course of action when no newer Microsoft-published version is available but vulnerability scanners continue to report critical or high-severity findings within Microsoft-managed software?
We are looking for guidance on how enterprise security teams should assess, report, and respond to these findings, particularly when the vulnerable component is embedded within a Microsoft application and remediation is wholly dependent on Microsoft's release process.