CVE-2023-24880: Windows SmartScreen Security Feature Bypass Vulnerability
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.
Other sources
Windows SmartScreen Security Feature Bypass Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.1696Patch KB5023698 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.2728Patch KB5023696 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.2728Patch KB5023696 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1607Fixed in 10.0.20348.1602Patch KB5023786 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.4131Patch KB5023702 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.5786Patch KB5023697 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.1413Patch KB5023706 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.2728Patch KB5023696
Event History
Frequently Asked Questions
What is CVE-2023-24880?
CVE-2023-24880 is a Microsoft Windows SmartScreen security feature bypass vulnerability that allows an attacker to evade Mark of the Web (MOTW) defenses.
What is the severity of CVE-2023-24880?
CVE-2023-24880 has a severity rating of 4.4, which is considered medium.
How does CVE-2023-24880 affect Microsoft Windows?
CVE-2023-24880 affects Microsoft Windows by bypassing the SmartScreen security feature, allowing attackers to evade MOTW defenses through a malicious file.
How can I fix CVE-2023-24880 on Windows 10?
To fix CVE-2023-24880 on Windows 10 version 21H2, install the patch provided by Microsoft (KB5023696) from the official Microsoft catalog update site.
How can I fix CVE-2023-24880 on Windows 11?
To fix CVE-2023-24880 on Windows 11 version 21H2, install the patch provided by Microsoft (KB5023698) from the official Microsoft catalog update site.