Forum Discussion

david147brown's avatar
david147brown
New Member
1 year ago

MS needs to update OpenSSL within On Premise Data Gateway

MS seem to keep shipping software with OpenSSL vulnerabilities, and dont update openSSL to the latest versions.

 

This means that I have security vulnerabilities all over the place to do with

 

PowerBI desktop

On Premises data gateway

Visual Studio

as well as a raft of Azure VM configuration and management extensions

 

Does anyone know if they get round to updating these?

4 Replies

  • Anonymous's avatar
    Anonymous
    Not applicable

    Hi david147brown,
    It looks like you have a very serious problem, and it is recommended that users regularly check for security bulletins issued by the Microsoft Security Response Center (MSRC).
    I would recommend checking regularly for security bulletins issued by the Microsoft Security Response Center (MSRC).The MSRC typically releases regular security updates related to various products including Power BI, On-Premises Data Gateway, and Visual Studio, etc., and if a new OpenSSL security vulnerability is disclosed, the If a new OpenSSL security vulnerability is disclosed, the MSRC will issue a patch or mitigation.

    Microsoft Security Response Center

    In order to enhance the security of On-Premises Data Gateway, it is recommended that you take more detailed cybersecurity measures to minimize the risk of potential attacks, here are the relevant documents that I found for you, I hope it will help you!
    View and manage on-premises data gateways - Power Platform | Microsoft Learn

    Azure network security groups overview | Microsoft Learn

    If none of the above measures are of practical help to you, and your feedback is particularly urgent, we recommend that you contact Microsoft's Technical Support team directly and submit a work order to expedite the process.
    This approach ensures that the issue is formally documented and may prompt a quicker response from the product team.

    Hope it helps!

    Best regards,
    Community Support Team_ Tom Shen

    If this post helps then please consider Accept it as the solution to help the other members find it more quickly.

     

  • pmemar's avatar
    pmemar
    Regular Visitor

    We’re seeing the same issue flagged by Microsoft Defender, which shows an attack path due to a vulnerability. The root cause is the outdated OpenSSL version in the Simba Spark ODBC connector, last updated 6 months ago.

    Since the on-premises data gateway uses this connector, it also inherits the vulnerability. We’re waiting for an update to fix this issue, and we believe Microsoft should address this risk promptly.

    • Anonymous's avatar
      Anonymous
      Not applicable

      Hi david147brown ,
      I am sorry to reply you after so long, at present Microsoft official has noticed this problem, about the Open ssl vulnerability, the solution given at present is that it will be fixed in the future desktop version, if the fixed version is released, I will notify you the latest desktop version number at the first time, I hope this can be helpful for your query!

      • pmemar's avatar
        pmemar
        Regular Visitor

        Hi Anonymous ,

         

        Unfortunately, the new update still suffers from the same vulnerability. We are looking forward to receiving an updated patch from Microsoft.