Junglewise Threat Intelligence

CVE-2023-24880: Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2023-24880 · Severity: critical · CVSS 4.4 · Exploited in the wild · Published 2023-03-14

Technologies: Microsoft Windows, Microsoft Windows 11, Microsoft Windows 10, Microsoft Windows Server. Vendors: Microsoft.

Executive brief

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to evade Mark of the Web (MOTW) defenses. By using a specially crafted malicious file, an attacker can bypass security warnings that would normally prevent the execution of untrusted files.

Affected products

  • Microsoft Windows 10 1607, 1809, 20H2, 21H2, 22H2
  • Microsoft Windows 11 21H2, 22H2
  • Microsoft Windows Server 2016, 2019, 2022

Timeline

  • 2023-03-14: disclosed
  • 2023-03-14: patched
  • 2023-03-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-03-14: exploited: Reported as exploited in the wild at time of publication.

Related threats