PT-2024-2715 · Microsoft · Windows+1

Dmitrij Lenz

+3

·

Published

2024-04-09

·

Updated

2026-02-06

·

CVE-2024-29988

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions prior to April 2024 Patch Tuesday
Description This issue is a security feature bypass vulnerability affecting the SmartScreen Prompt Security Feature in Microsoft Windows. The vulnerability allows attackers to bypass SmartScreen, potentially delivering malicious software to a target system. Exploitation requires user interaction, such as opening a specially crafted file or clicking a malicious link. Reports indicate that this vulnerability is being actively exploited in the wild, and it is related to CVE-2024-21412, which has been exploited by the Water Hydra APT group. The vulnerability impacts the security of web page shortcut prompts.
Recommendations Apply the updates released during the April 2024 Patch Tuesday to address this vulnerability.

Exploit

Fix

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

BDU:2024-02831
CVE-2024-29988
ZDI-24-361

Affected Products

Smartscreen
Windows