Wingetlywingetly
← All apps

FireDaemon OpenSSL

by FireDaemonv4.0.2

Last updated

FireDaemon OpenSSL Installer

Install with winget

$ winget install --id FireDaemon.OpenSSL --exact --version 4.0.2

Run in Command Prompt, PowerShell, or Windows Terminal. Prompts for any agreements.

Silent install command for FireDaemon OpenSSL

FireDaemon OpenSSL uses EXE. The silent install switches are /exenoui /qn /norestart REBOOT=ReallySuppress ADJUSTSYSTEMPATHENV=yes.

One-line silent install (x64, machine scope)
FireDaemon-OpenSSL-x64-4.0.2.exe /exenoui /qn /norestart REBOOT=ReallySuppress ADJUSTSYSTEMPATHENV=yes

See the full silent install reference for FireDaemon OpenSSL

Built by Pckgr

For Intune admins

Stop chasing app updates. Pckgr patches them for you.

Automated application patching for Microsoft Intune. Pckgr keeps a curated library of 1,000+ apps continuously up-to-date in your tenant via Microsoft Graph - no manual repackaging, no chasing vendor sites.

Start free 30-day trial

No credit card required.

About

OpenSSL is a popular open-source software library and command-line tool that provides a robust, full-featured set of cryptographic functions to secure communications over computer networks. It implements the Transport Layer Security (TLS) protocol, which is used to encrypt data transmissions across a wide range of applications including web servers, email, VPNs, databases, and IoT devices. OpenSSL provides a wide range of cryptographic functions, including symmetric encryption, public-key encryption, message digest and hash functions, digital signatures, and random number generation. It supports a large number of cryptographic algorithms, including AES, RSA, ECDSA, and Diffie-Hellman, as well as post-quantum algorithms such as ML-KEM, ML-DSA, and SLH-DSA. In addition to cryptographic functions, OpenSSL provides utilities for generating and managing digital certificates and keys, creating and verifying digital signatures, and performing TLS handshakes and negotiations. It also includes a comprehensive command-line tool for certificate management, key generation, TLS diagnostics, and general cryptographic operations.

The key advantages of using the FireDaemon OpenSSL over others that are available are:

- Recognised Source: Listed by the OpenSSL Project as a trusted third-party binary distribution for Windows

- Zero Dependencies: No Microsoft Visual C++ Redistributables required. We leverage the native Windows Universal C Runtime (UCRT) for "clean system" stability

- EV-Signed Integrity: All installers and binaries are digitally signed with a Sectigo Extended Validation (EV) certificate to ensure authenticity and bypass Windows SmartScreen warnings

- Flexible Deployment: Packaged for standalone, portable, or embedded use cases

- Verifiable Security: Every build is pre-scanned via VirusTotal and backed by our publicly available build scripts for total transparency

- Compliance Ready: Designed for developers and sysadmins who require a verifiable, audit-ready OpenSSL environment

Installers · v4.0.2

ArchitectureTypeScopeInstallDownload
x64EXEmachineDirect

Copy a command tailored to that specific architecture, type, and scope - useful when winget would otherwise pick a different default.

Security

25 known CVEs via NVD

  • high7.5Patched in wingetCVE-2026-9076affects before 1.0.2zq, 1.1.1zh, 3.0.21, +3 moreJun 9, 2026

    Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in kek_unwrap_key(). Impact summary: A heap buffer over-read may trigger a crash...

  • high8.1Patched in wingetCVE-2026-7383affects before 1.0.2zq, 1.1.1zh, 3.0.21, +3 moreJun 9, 2026

    Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow. Impact summary: A heap buffer overflow may lead to a crash or possibly attacker controlled code execution or other undefin...

  • high8.8Patched in wingetCVE-2026-45447affects before 1.0.2zq, 1.1.1zh, 3.0.21, +3 moreJun 9, 2026

    Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS...

  • medium4.8Patched in wingetCVE-2026-45446affects before 3.0.21, 3.4.6, 3.5.7, 3.6.3Jun 9, 2026

    Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages. Impact summary: An attacker can forge empty messages with arbitr...

  • high7.5Patched in wingetCVE-2026-45445affects before 3.0.21, 3.4.6, 3.5.7, 3.6.3Jun 9, 2026

    Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded. Impact summary: Every message encrypted under the same key uses the same effective nonce r...

  • medium6.2Patched in wingetCVE-2026-42771affects v4.0.0Jun 9, 2026

    Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, such as during S/MIME message validation, an out of bounds read can happen. Impact summary: This out of bounds read will not directly exfiltrate the data read...

  • low3.7Patched in wingetCVE-2026-42770affects before 3.0.21, 3.4.6, 3.5.7, 3.6.3Jun 9, 2026

    Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parameters, a forged q = r (a small...

  • medium5.3Patched in wingetCVE-2026-42769affects before 3.4.6, 3.5.7, 3.6.3Jun 9, 2026

    Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual, which could lead to escalation of credentials from the Registration Aut...

Showing 8 of 25. Source: NVD, updated 3h ago. Patch status is best-effort: NVD's fix version is compared against the latest version in winget, but the two version formats don't always align. Confirm with the vendor advisory before treating any specific build as safe.

See a CVE that affects your fleet? Push the patched version to Intune in one click with Pckgr - automated patching is the only way to keep up.

Related apps

  • FireDaemon ZeroFireDaemon
    FireDaemon.FireDaemonZerov4.0.8

    Switch to and manage interactive services on Session 0

  • FireDaemon FusionFireDaemon
    FireDaemon.FireDaemonFusionv8.1.7

    Manage FireDaemon Pro and Windows services in your browser.

  • FireDaemon ProFireDaemon
    FireDaemon.FireDaemonProv6.4.2

    Run any program, application, or script as a Microsoft Windows service 24/7.

  • FireDaemon LozengeFireDaemon
    FireDaemon.FireDaemonLozengev3.1.3

    Your lozenge for everyday cryptographic tasks - Compute multiple hashes for files, Create self-signed certificates, Generate Certificate Signing Requests.

  • Certify OneFireDaemon
    FireDaemon.CertifyOnev4.2.3

    Verify the confidentiality, integrity, authenticity, and availability of encrypted communications.

  • System InformerWinsider Seminars & Solutions, Inc.
    WinsiderSS.SystemInformerv4.0.26241.138

    System Informer is a free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware.

More from FireDaemon or browse cryptography, cybersecurity, openssl.

Frequently asked questions

How do I install FireDaemon OpenSSL on Windows?
Open Windows Terminal, PowerShell, or Command Prompt and run: winget install --id FireDaemon.OpenSSL --exact --version 4.0.2. winget downloads the installer from FireDaemon and runs it. Requires Windows 10 (1809+) or Windows 11.
How do I install FireDaemon OpenSSL silently for unattended deployment?
Add --silent and accept the agreements upfront: winget install --id FireDaemon.OpenSSL --exact 4.0.2 --silent --accept-package-agreements --accept-source-agreements. This is the variant Intune, Configuration Manager, and other deployment tools should use.
What are the silent install switches for FireDaemon OpenSSL?
FireDaemon OpenSSL uses EXE. Run the downloaded installer with: FireDaemon-OpenSSL-x64-4.0.2.exe /exenoui /qn /norestart REBOOT=ReallySuppress ADJUSTSYSTEMPATHENV=yes. The silent switches are /exenoui /qn /norestart REBOOT=ReallySuppress ADJUSTSYSTEMPATHENV=yes.
How do I uninstall FireDaemon OpenSSL via winget?
Run: winget uninstall --id FireDaemon.OpenSSL --exact. Add --silent for unattended uninstalls. winget will use the registered uninstaller from FireDaemon OpenSSL's Apps & Features entry.
Is FireDaemon OpenSSL free?
FireDaemon OpenSSL is distributed under Apache-2.0. Refer to the publisher (https://www.firedaemon.com/firedaemon-openssl) for the full license terms - Wingetly itself does not charge for installation.
Does FireDaemon OpenSSL work on Windows 10?
Yes, as long as your Windows 10 build supports winget (1809 or newer). winget ships with App Installer on Windows 10/11 and pulls FireDaemon OpenSSL directly from the publisher.
How do I keep FireDaemon OpenSSL up to date?
Run winget upgrade --id FireDaemon.OpenSSL --exact, or winget upgrade --all to update everything winget tracks. We index 10 versions of FireDaemon OpenSSL from microsoft/winget-pkgs.

Recent versions

  • 4.0.2latest
  • 4.0.1
  • 4.0.0.3
  • 4.0.0.1
  • 4.0.0
  • 3.6.2
  • 3.6.1
  • 3.6.0
  • 3.5.3
  • 3.5.2