Skip to main content
Question

OpenSSL Vulnerabilities still in Latest Versions of Box Drive

  • May 27, 2025
  • 1 reply
  • 11 views

Forum|alt.badge.img

The latest version of Box Drive for Windows (2.41.226) still contains outdated OpenSSL binaries (libcrypto-3 3.0.11 and libssl-3 3.0.11) which are vulnerable to several CVEs including CVE-2024-4741 (CVSS 8.1). Please patch these binaries as they are currently greatly elevating our enterprise vulnerability score across several security platforms.

1 reply

Forum|alt.badge.img
  • Author
  • Box Employee
  • 34740 replies
  • May 27, 2025

Hi Rona

I use Box Drive 2.43.205 but why Openssl is still 3.0.11.0, how can I update it?