Junglewise Threat Intelligence

CVE-2024-21412: Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability

CVE-2024-21412 · Severity: critical · CVSS 8.1 · Exploited in the wild · Published 2024-02-13

Technologies: Microsoft Windows 11 23h2, Microsoft Windows, Microsoft Windows 10 22h2, Microsoft Windows Server 2019, Microsoft Windows 10 21h2, Microsoft Windows 10 1809, Microsoft Windows Server 2022, Microsoft Windows Server 2022 23h2, Microsoft Windows 11 22h2. Vendors: Microsoft.

Executive brief

Microsoft Windows Internet Shortcut Files (.url) contain a security feature bypass vulnerability that allows an attacker to bypass Mark of the Web (MotW) protections. An attacker can exploit this by crafting a malicious file that, when opened by a user, executes without the expected security warnings.

Affected products

  • Microsoft Windows 10 1809 up to (excluding) 10.0.17763.5458
  • Microsoft Windows 10 21H2 up to (excluding) 10.0.19044.4046
  • Microsoft Windows 10 22H2 up to (excluding) 10.0.19045.4046
  • Microsoft Windows 11 21H2 up to (excluding) 10.0.22000.2777
  • Microsoft Windows 11 22H2 up to (excluding) 10.0.22621.3155
  • Microsoft Windows 11 23H2 up to (excluding) 10.0.22631.3155
  • Microsoft Windows Server 2019 up to (excluding) 10.0.17763.5458
  • Microsoft Windows Server 2022 up to (excluding) 10.0.20348.2322
  • Microsoft Windows Server 2022 23H2 up to (excluding) 10.0.25398.709

Timeline

  • 2024-02-13: disclosed
  • 2024-02-13: patched
  • 2024-02-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-02-13: exploited: Reported as exploited in the wild at time of publication.

Related threats