Junglewise Threat Intelligence

CVE-2024-21351: Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2024-21351 · Severity: critical · CVSS 7.6 · Exploited in the wild · Published 2024-02-13

Technologies: Microsoft Windows, Microsoft Windows Server 2016, Microsoft Windows 11, Microsoft Windows Server 2022 23h2, Microsoft Windows Server 2022, Microsoft Windows Server 2019, Microsoft Windows 10. Vendors: Microsoft.

Executive brief

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the user experience and inject code. Successful exploitation could lead to unauthorized code execution, data exposure, and impacts on system availability.

Affected products

  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 21H2, 22H2, 23H2
  • Microsoft Windows Server 2016 -
  • Microsoft Windows Server 2019 -
  • Microsoft Windows Server 2022 -
  • Microsoft Windows Server 2022 23H2 -

Timeline

  • 2024-02-13: disclosed
  • 2024-02-13: patched
  • 2024-02-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-02-13: exploited: Reported as exploited in the wild at time of publication.

Related threats