Executive brief
Microsoft Windows Defender SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the 'Open File - Security Warning' prompt. Successful exploitation requires a user to open a specially crafted file, potentially leading to unauthorized code execution.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 21H2, 22H2
- Microsoft Windows Server 2016
- Microsoft Windows Server 2019
- Microsoft Windows Server 2022
Timeline
- 2023-07-11: disclosed
- 2023-07-11: patched
- 2023-07-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-07-11: exploited: Reported as exploited in the wild at time of publication.