CVE-2023-36025: Windows SmartScreen Security Feature Bypass Vulnerability
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts.
Other sources
Windows SmartScreen Security Feature Bypass Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.21668Patch KB5032249 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.24569Patch KB5032247 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.26816Patch KB5032250 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.22367Patch KB5032248 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.6452Patch KB5032197 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20308Patch KB5032199 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.531Patch KB5032202 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.2715Patch KB5032190 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.3693Patch KB5032189 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.2715Patch KB5032190 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.3693Patch KB5032189 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.2600Patch KB5032192 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.5122Patch KB5032196 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.2113Fixed in 10.0.20348.2091Patch KB5032304
Event History
Frequently Asked Questions
What is the severity of CVE-2023-36025?
CVE-2023-36025 is categorized as a security feature bypass vulnerability, which can potentially allow an attacker to bypass essential Windows Defender SmartScreen checks.
How do I fix CVE-2023-36025?
To fix CVE-2023-36025, you should apply the latest security updates provided by Microsoft for affected Windows versions.
Which software versions are affected by CVE-2023-36025?
CVE-2023-36025 affects various versions of Windows, including Windows 10, Windows 11, and Windows Server 2019.
Can CVE-2023-36025 be exploited remotely?
CVE-2023-36025 has the potential for remote exploitation if an attacker successfully bypasses the SmartScreen security checks.
What are the risks associated with CVE-2023-36025?
The risks for CVE-2023-36025 include the possibility for attackers to deliver malicious software undetected due to bypassed SmartScreen prompts.