Hello Sergio,
Thank you for posting question on Microsoft Windows Forum!
Based on the issue description. Well! The plausible explanation to this might be of that Microsoft Defender Vulnerability Management (MDVM) performs file-level binary inspection and flags embedded third-party libraries (like libcrypto.dll or libssl.dll) compiled directly into application packages. Probably because Microsoft treats library version updates inside client apps as routine maintenance rather than distinct product vulnerabilities.
On the other hand, the product teams for OneDrive and Photos (along with apps like Paint or Office Hub) might update their embedded OpenSSL dependencies on their own build release schedules. An app can be on its "latest" public build while still shipping an older OpenSSL build branch. Also for orphaned Cache & installer files. MDVM scans the entire disk surface. It frequently flags inactive, legacy binaries sitting in installer caches or temp directories.
For an enterprise environment. It is worth considering to open a Microsoft support case for this.
You can refer to the following link for further reference.
Hope the above information is helpful!