First published: Tue Apr 09 2024(Updated: )
Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-38831 and CVE-2024-21412 to execute a malicious file.
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =21H2 | |
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2022 | ||
Microsoft Windows 11 | =21H2 | |
Microsoft Windows 11 | =22H2 | |
Microsoft Windows 11 | =22H2 | |
Microsoft Windows Server 2022 | ||
Microsoft Windows 11 | =21H2 | |
Microsoft Windows 10 | =22H2 | |
Microsoft Windows Server 2022, 23H2 Edition | ||
Microsoft Windows 10 | =21H2 | |
Microsoft Windows 10 | =21H2 | |
Microsoft Windows 11 | =23H2 | |
Microsoft Windows 10 | =22H2 | |
Microsoft Windows Server 2019 | ||
Microsoft Windows 10 | =22H2 | |
Microsoft Windows 11 | =23H2 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =1809 | |
Microsoft SmartScreen Prompt | ||
Microsoft Windows 10 1809 | <10.0.17763.5696 | |
Microsoft Windows 10 1809 | <10.0.17763.5696 | |
Microsoft Windows 10 1809 | <10.0.17763.5696 | |
Microsoft Windows 10 21h2 | <10.0.19044.4291 | |
Microsoft Windows 10 22h2 | <10.0.19045.4291 | |
Microsoft Windows 11 21h2 | <10.0.22000.2899 | |
Microsoft Windows 11 22h2 | <10.0.22621.3447 | |
Microsoft Windows 11 23h2 | <10.0.22631.3447 | |
Microsoft Windows Server 2019 | <10.0.17763.5696 | |
Microsoft Windows Server 2022 | <10.0.20348.2402 | |
Microsoft Windows Server 2022 23h2 | <10.0.25398.830 |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)