First published: Tue Jul 11 2023(Updated: )
Microsoft Windows Defender SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the Open File - Security Warning prompt.
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =21H2 | |
Microsoft Windows 10 | =22H2 | |
Microsoft Windows 10 | =22H2 | |
Microsoft Windows 10 | =22H2 | |
Microsoft Windows 10 | =21H2 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =21H2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | ||
Microsoft Windows 10 | <10.0.14393.6085 | |
Microsoft Windows 10 | <10.0.17763.4645 | |
Microsoft Windows 10 | <10.0.19041.3208 | |
Microsoft Windows 10 22H2 | <10.0.19045.3208 | |
Windows 11 | <10.0.22000.2176 | |
Windows 11 | <10.0.22621.1992 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2022 | ||
Microsoft Windows | ||
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2019 | ||
Windows 11 | =22H2 | |
Windows 11 | =22H2 | |
Windows 11 | =21H2 | |
Windows 11 | =21H2 | |
Microsoft Windows Server 2022 | ||
Microsoft Windows Server 2022 |
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-32049 is considered a security feature bypass vulnerability.
To fix CVE-2023-32049, apply the recommended security patches from Microsoft for the affected versions of Windows.
CVE-2023-32049 affects various versions of Microsoft Windows, including Windows 10 and Windows 11.
CVE-2023-32049 is a local exploit that allows an attacker to bypass security prompts on affected systems.
The potential impact of CVE-2023-32049 includes unauthorized execution of files without user consent due to the bypass of security warnings.