Our Microsoft Defender Endpoint reported vulnerabilities in Openssl for the following GoToAssist agent files. I asked GoToAssist support but they don't have an estimated time frame of resolution. Should we find other remote tool?
c:\program files\goto\gotoassist agent desktop console\libssl-3-x64.dll
c:\program files\goto\gotoassist agent desktop console\libcrypto-3-x64.dll
Associated CVEs (Severity): CVE-2023-2650 (High), CVE-2023-4807 (High), CVE-2023-0464 (Medium), CVE-2023-6129 (Medium), CVE-2023-2975 (Medium), CVE-2023-5363 (Medium).
What version of agent(s) are you on? I have both V4 and V5 installed and I do not have the directory: c:\program files\goto .
On my Win 10 computer, the DLL files you listed are stored at AppData\Local\Programs\LogMeIn\GoToAssist Agent Desktop Console
Download Windows 64-bit version from https://help.gotoassist.com/remote-support/help/gotoassist-remote-support-agent-desktop-console-bet...
Was already on 64-bit version of V5 desktop, version 5.9.1.101
Downloaded from your link and reinstalled 64-bit version. Same version appeared: 5.9.1.101.
None of the two DLL files you listed are located at c:\program files\goto\gotoassist agent desktop console. This directory does not exist on my end. Still located at: AppData\Local\Programs\LogMeIn\GoToAssist Agent Desktop Console
Hi @IBUS Welcome to the GoTo Community. @Kaz111 great to see you and thanks for your help here.
Our team is currently evaluating this and we will post an update as soon as we learn more on the situation. Thanks very much for your patience and reports.
I downloaded 64-bit version (G2AAgentDesktopConsole-x64.msi) and installed, then files are extracted under C:\Program Files\GoTo\GoToAssist Agent Desktop Console. Our OS is Win11.
Interesting. I wonder why the difference in installation and file location between Win 10 (Pro in my case) vs. your Win 11??? Do you have anything under: AppData\Local\Programs\LogMeIn\GoToAssist Agent Desktop Console
There is no LogMeIn folder under my AppData\Local\Programs
Hi @IBUS, welcome to the community.
I can confirm that we have an update to GoToAssist Remote Support v5 coming that will update the version of OpenSSL being used (final release date still to be confirmed).
With GoToAssist Remote Support v4 I am waiting for some final details, but my understanding is that because we accepts TLS v1-2 on the server side this is not a concern.
Thank you for the good news. I will wait it.