Hello,
We noticed that FortiClient 7.4.3.1790 loads the following OpenSSL‑related DLLs:
These files appear to be based on OpenSSL 3.1.7, and Microsoft Defender for Endpoint is associating them with:
Could you please clarify the following?
For the OpenSSL 3.1.7 components bundled with FortiClient 7.4.3.1790:
Is there an existing or upcoming FortiClient build that includes a more recent OpenSSL version (e.g. 3.1.8 or 3.1.9)?
Is there a Fortinet security advisory confirming whether FortiClient is impacted (or not) by CVE‑2024‑13176?
We are trying to determine whether this should trigger remediation or if it is likely a false positive from Microsoft Defender.
Thank you.
Hi @FlorentG ,
As a part of security best practice, Fortinet upgrades 3rd party components from time to time. The OpenSSL version can be confirmed by checking the file under "... Fortinet\FortiClient\x86\libcrypto-3.dll". The properties of the file would show you the version of OpenSSL.
Version 7.4.4 should have OpenSSL 3.4.1 and 7.4.5 comes with 3.5.4. You can upgrade to these versions and get the latest OpenSSL DLLs.
| User | Count |
|---|---|
| 2895 | |
| 1449 | |
| 850 | |
| 825 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.