Executive brief
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the user experience and inject code. Successful exploitation could lead to unauthorized code execution, data exposure, and impacts on system availability.
Affected products
- Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 21H2, 22H2, 23H2
- Microsoft Windows Server 2016 -
- Microsoft Windows Server 2019 -
- Microsoft Windows Server 2022 -
- Microsoft Windows Server 2022 23H2 -
Timeline
- 2024-02-13: disclosed
- 2024-02-13: patched
- 2024-02-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-02-13: exploited: Reported as exploited in the wild at time of publication.