FortiClient 7.4.3.1790 – OpenSSL 3.1.7 DLLs flagged by Defender (CVE‑2024‑13176)
Hello,
We noticed that FortiClient 7.4.3.1790 loads the following OpenSSL‑related DLLs:
- libcrypto-3-x64.dll
- libssl-3-x64.dll
- libcrypto-3.dll
- libssl-3.dll
These files appear to be based on OpenSSL 3.1.7, and Microsoft Defender for Endpoint is associating them with:
- CVE‑2024‑13176
- plus one additional vulnerability affecting OpenSSL 3.1.x
Could you please clarify the following?
For the OpenSSL 3.1.7 components bundled with FortiClient 7.4.3.1790:
- Are these builds affected by the vulnerabilities?
- Or are they patched/customized by Fortinet, even though this is not mentioned in the release notes?
Is there an existing or upcoming FortiClient build that includes a more recent OpenSSL version (e.g. 3.1.8 or 3.1.9)?
Is there a Fortinet security advisory confirming whether FortiClient is impacted (or not) by CVE‑2024‑13176?
We are trying to determine whether this should trigger remediation or if it is likely a false positive from Microsoft Defender.
Thank you.
