Junglewise Threat Intelligence

CVE-2024-29988: Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability

CVE-2024-29988 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2024-04-30

Technologies: Microsoft Windows Server 2019, Microsoft Windows Server 2022 23h2, Microsoft Windows Server 2022, Microsoft Windows 11, Microsoft Windows 10. Vendors: Microsoft.

Executive brief

Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) protection. This flaw can be chained with other vulnerabilities to execute malicious files without triggering expected security warnings.

Affected products

  • Microsoft Windows 10 1809, 21H2, 22H2
  • Microsoft Windows 11 21H2, 22H2, 23H2
  • Microsoft Windows Server 2019 All versions
  • Microsoft Windows Server 2022 All versions
  • Microsoft Windows Server 2022 23H2 All versions

Timeline

  • 2024-04-09: disclosed: Initial disclosure by Microsoft Corporation
  • 2024-04-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-04-30: advisory: NVD publication date
  • 2024-05-03: patched: NIST analysis and patch information updated