Executive brief
Microsoft Windows Internet Shortcut Files (.url) contain a security feature bypass vulnerability that allows an attacker to bypass Mark of the Web (MotW) protections. An attacker can exploit this by crafting a malicious file that, when opened by a user, executes without the expected security warnings.
Affected products
- Microsoft Windows 10 1809 up to (excluding) 10.0.17763.5458
- Microsoft Windows 10 21H2 up to (excluding) 10.0.19044.4046
- Microsoft Windows 10 22H2 up to (excluding) 10.0.19045.4046
- Microsoft Windows 11 21H2 up to (excluding) 10.0.22000.2777
- Microsoft Windows 11 22H2 up to (excluding) 10.0.22621.3155
- Microsoft Windows 11 23H2 up to (excluding) 10.0.22631.3155
- Microsoft Windows Server 2019 up to (excluding) 10.0.17763.5458
- Microsoft Windows Server 2022 up to (excluding) 10.0.20348.2322
- Microsoft Windows Server 2022 23H2 up to (excluding) 10.0.25398.709
Timeline
- 2024-02-13: disclosed
- 2024-02-13: patched
- 2024-02-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-02-13: exploited: Reported as exploited in the wild at time of publication.