Executive brief
A security bypass vulnerability exists in the Windows 'Mark of the Web' feature, which is a safety mechanism that flags files downloaded from the internet to trigger security warnings. An attacker could exploit this to trick a user into running a malicious file without the usual security alerts appearing. This could lead to unauthorized software execution or a compromise of the user's workstation.
Technical details
A protection mechanism failure (CWE-693) exists in the Windows Mark of the Web (MOTW) component. The vulnerability allows a remote, unauthenticated attacker to bypass security restrictions by crafting a file that does not properly receive or honor the MOTW designation when downloaded. Exploitation requires user interaction, typically involving a user opening a specially crafted file or visiting a malicious website. Successful exploitation allows the attacker to circumvent security features like SmartScreen or Protected View in Office, potentially leading to the execution of arbitrary code or unauthorized system changes. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-06-09: advisory: Initial disclosure by Microsoft and NVD.
- 2026-06-09: patched: Security updates made available via Microsoft Update Guide.