Zum Inhalt der Seite gehen


Via another "crazy security scanner" report, I learn that #libcurl is installed in a #Microsoft Office and/or Teams install on Windows? According to the reddit post, in a normal install.

Does anyone know more?

The reddit page mentioning this: https://www.reddit.com/r/sysadmin/comments/1hx9eib/libcurl_vulnerability_in_office_and_teams/?sort=new

The libcurl mailing list post:

https://curl.se/mail/lib-2025-01/0086.html
That looks to be less Office, and more the Salesforce Connector for Office. And Salesforce does regularly include curl - and usually an outdated one.
bagder@mastodon.social

Yes, it's a driver to interact with a saleforce database. If not needed, it's possible to uninstall the ODBC driver.

In the reddit post, no one really has an idea what's going on, but using security reports and then only push the incident numbers back to 0 instead of understanding what's going on.