cancel
Showing results for 
Search instead for 
Did you mean: 
IBUS
Active Contributor

GoToAssist Agent Vulnerabilities

Our Microsoft Defender Endpoint reported vulnerabilities in Openssl for the following GoToAssist agent files. I asked GoToAssist support but they don't have an estimated time frame of resolution. Should we find other remote tool?

 

c:\program files\goto\gotoassist agent desktop console\libssl-3-x64.dll
c:\program files\goto\gotoassist agent desktop console\libcrypto-3-x64.dll

 

Associated CVEs (Severity): CVE-2023-2650 (High), CVE-2023-4807 (High), CVE-2023-0464 (Medium), CVE-2023-6129 (Medium), CVE-2023-2975 (Medium), CVE-2023-5363 (Medium).

 

9 REPLIES 9
Kaz111
Active Contributor

Re: GoToAssist Agent Vulnerabilities

What version of agent(s) are you on?  I have both V4 and V5 installed and I do not have the directory: c:\program files\goto .

 

On my Win 10 computer, the DLL files you listed are stored at AppData\Local\Programs\LogMeIn\GoToAssist Agent Desktop Console

IBUS
Active Contributor

Re: GoToAssist Agent Vulnerabilities

Kaz111
Active Contributor

Re: GoToAssist Agent Vulnerabilities

Was already on 64-bit version of V5 desktop, version 5.9.1.101

 

Downloaded from your link and reinstalled 64-bit version.  Same version appeared: 5.9.1.101.

 

None of the two DLL files you listed are located at c:\program files\goto\gotoassist agent desktop console.  This directory does not exist on my end.  Still located at: AppData\Local\Programs\LogMeIn\GoToAssist Agent Desktop Console

KateG
GoTo Moderator

Re: GoToAssist Agent Vulnerabilities

Hi @IBUS Welcome to the GoTo Community. @Kaz111 great to see you and thanks for your help here. 

 

Our team is currently evaluating this and we will post an update as soon as we learn more on the situation. Thanks very much for your patience and reports.  


Kate is a member of the GoTo Community Care Team.

Was your question answered? Please mark it as an Accepted Solution.
Was a post helpful or informative? Give it a Kudo!


Free new user and admin training
IBUS
Active Contributor

Re: GoToAssist Agent Vulnerabilities

I downloaded 64-bit version (G2AAgentDesktopConsole-x64.msi) and installed, then files are extracted under C:\Program Files\GoTo\GoToAssist Agent Desktop Console. Our OS is Win11.

Kaz111
Active Contributor

Re: GoToAssist Agent Vulnerabilities

Interesting.  I wonder why the difference in installation and file location between Win 10 (Pro in my case) vs. your Win 11???  Do you have anything under: AppData\Local\Programs\LogMeIn\GoToAssist Agent Desktop Console

IBUS
Active Contributor

Re: GoToAssist Agent Vulnerabilities

There is no LogMeIn folder under my AppData\Local\Programs

GlennD
GoTo Manager

Re: GoToAssist Agent Vulnerabilities

Hi @IBUS, welcome to the community.

 

I can confirm that we have an update to GoToAssist Remote Support v5 coming that will update the version of OpenSSL being used (final release date still to be confirmed). 

With GoToAssist Remote Support v4 I am waiting for some final details, but my understanding is that because we accepts TLS v1-2 on the server side this is not a concern.

 

 

Glenn is a member of the GoTo Community Care Team.

Was your question answered? Please mark it as an Accepted Solution.
Was a post helpful or informative? Give it a Kudo!.
Do you want a new feature added? Make sure you Kudo (vote) for the Idea

Free user and admin training
IBUS
Active Contributor

Re: GoToAssist Agent Vulnerabilities

Thank you for the good news. I will wait it.