Forum Discussion

IBUS's avatar
IBUS
Active Contributor
12 months ago

GoToAssist Agent Vulnerabilities

Our Microsoft Defender Endpoint reported vulnerabilities in Openssl for the following GoToAssist agent files. I asked GoToAssist support but they don't have an estimated time frame of resolution. Should we find other remote tool?

 

c:\program files\goto\gotoassist agent desktop console\libssl-3-x64.dll
c:\program files\goto\gotoassist agent desktop console\libcrypto-3-x64.dll

 

Associated CVEs (Severity): CVE-2023-2650 (High), CVE-2023-4807 (High), CVE-2023-0464 (Medium), CVE-2023-6129 (Medium), CVE-2023-2975 (Medium), CVE-2023-5363 (Medium).

 

14 Replies

  • KateG's avatar
    KateG
    GoTo Manager
    12 months ago

    Hi IBUS Welcome to the GoTo Community. Kaz111 great to see you and thanks for your help here. 

     

    Our team is currently evaluating this and we will post an update as soon as we learn more on the situation. Thanks very much for your patience and reports.  

  • Kaz111's avatar
    Kaz111
    Active Contributor
    12 months ago

    Was already on 64-bit version of V5 desktop, version 5.9.1.101

     

    Downloaded from your link and reinstalled 64-bit version.  Same version appeared: 5.9.1.101.

     

    None of the two DLL files you listed are located at c:\program files\goto\gotoassist agent desktop console.  This directory does not exist on my end.  Still located at: AppData\Local\Programs\LogMeIn\GoToAssist Agent Desktop Console

  • Kaz111's avatar
    Kaz111
    Active Contributor
    12 months ago

    What version of agent(s) are you on?  I have both V4 and V5 installed and I do not have the directory: c:\program files\goto .

     

    On my Win 10 computer, the DLL files you listed are stored at AppData\Local\Programs\LogMeIn\GoToAssist Agent Desktop Console