CVE-2024-21412: Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability
Internet Shortcut Files Security Feature Bypass Vulnerability
Other sources
Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.5458Patch KB5034768 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.3155Patch KB5034765 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.2777Patch KB5034766 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.2322Patch KB5034770 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.4046Patch KB5034763 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.709Patch KB5034769 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.3155Patch KB5034765 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.4046Patch KB5034763
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21412?
CVE-2024-21412 is classified as a security feature bypass vulnerability which can lead to unauthorized actions.
How do I fix CVE-2024-21412?
To fix CVE-2024-21412, apply the appropriate Microsoft security updates as detailed in their support documentation.
Which Microsoft products are affected by CVE-2024-21412?
CVE-2024-21412 affects various versions of Windows 10, Windows 11, and Windows Server products.
Can CVE-2024-21412 be exploited remotely?
Yes, CVE-2024-21412 can potentially be exploited remotely to bypass security features.
Is there a workaround for CVE-2024-21412?
There are no documented workarounds for CVE-2024-21412; patching is the recommended course of action.