Executive brief
Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) protection. This flaw can be chained with other vulnerabilities to execute malicious files without triggering expected security warnings.
Affected products
- Microsoft Windows 10 1809, 21H2, 22H2
- Microsoft Windows 11 21H2, 22H2, 23H2
- Microsoft Windows Server 2019 All versions
- Microsoft Windows Server 2022 All versions
- Microsoft Windows Server 2022 23H2 All versions
Timeline
- 2024-04-09: disclosed: Initial disclosure by Microsoft Corporation
- 2024-04-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-04-30: advisory: NVD publication date
- 2024-05-03: patched: NIST analysis and patch information updated