Junglewise Threat Intelligence

CVE-2024-38213: Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2024-38213 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2024-08-13

Technologies: Microsoft Windows, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows Server 2012, Microsoft Windows 11, Microsoft Windows Server 2016. Vendors: Microsoft.

Executive brief

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) protections. An attacker can exploit this by hosting a malicious file on a website or share and tricking a user into opening it, effectively bypassing the SmartScreen user experience.

Affected products

  • Microsoft Windows 10 up to (excluding) 10.0.10240.20680
  • Microsoft Windows 11 up to (excluding) 10.0.22000.3019
  • Microsoft Windows Server 2012 up to (excluding) 6.2.9200.24919
  • Microsoft Windows Server 2016 up to (excluding) 10.0.14393.7070
  • Microsoft Windows Server 2019 up to (excluding) 10.0.17763.5936
  • Microsoft Windows Server 2022 up to (excluding) 10.0.20348.2522

Timeline

  • 2024-08-13: disclosed
  • 2024-08-13: patched
  • 2024-08-13: kev added: Added to CISA KEV catalog due to active exploitation.
  • 2024-08-13: exploited

Related threats