CVE-2024-21351: Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience and inject code to potentially gain code execution, which could lead to some data exposure, lack of system availability, or both.
Other sources
Windows SmartScreen Security Feature Bypass Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.6709Patch KB5034767 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.4046Patch KB5034763 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20469Patch KB5034774 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.3155Patch KB5034765 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.2777Patch KB5034766 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.5458Patch KB5034768 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.4046Patch KB5034763 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.2322Patch KB5034770 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.3155Patch KB5034765
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-21351?
CVE-2024-21351 is classified as a security feature bypass vulnerability with potential for code execution.
How do I fix CVE-2024-21351?
To fix CVE-2024-21351, apply the security patches provided by Microsoft for the affected versions of Windows.
What versions of Windows are affected by CVE-2024-21351?
CVE-2024-21351 affects multiple versions of Windows, including Windows 10, Windows 11, and Windows Server.
What potential impact does CVE-2024-21351 have on systems?
The impact of CVE-2024-21351 can include unauthorized code execution, which may lead to data exposure or loss of system availability.
How can I identify if my Windows system is vulnerable to CVE-2024-21351?
You can determine your system's vulnerability to CVE-2024-21351 by checking the installed version of Windows against the list of affected products and whether recent patches have been applied.