CVE-2023-32049: Windows SmartScreen Security Feature Bypass Vulnerability
Microsoft Windows Defender SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the Open File - Security Warning prompt.
Other sources
Windows SmartScreen Security Feature Bypass Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.6085Patch KB5028169 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.3208Patch KB5028166 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.3208Patch KB5028166 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.1992Patch KB5028185 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.2176Patch KB5028182 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1850Patch KB5028171 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.4645Patch KB5028168
Event History
Frequently Asked Questions
What is the severity of CVE-2023-32049?
CVE-2023-32049 is considered a security feature bypass vulnerability.
How do I fix CVE-2023-32049?
To fix CVE-2023-32049, apply the recommended security patches from Microsoft for the affected versions of Windows.
Which Microsoft products are affected by CVE-2023-32049?
CVE-2023-32049 affects various versions of Microsoft Windows, including Windows 10 and Windows 11.
Can CVE-2023-32049 be exploited remotely?
CVE-2023-32049 is a local exploit that allows an attacker to bypass security prompts on affected systems.
What are the potential impacts of CVE-2023-32049?
The potential impact of CVE-2023-32049 includes unauthorized execution of files without user consent due to the bypass of security warnings.