PT-2024-5548 · Microsoft · Windows

Gothburz

+2

·

Published

2024-08-13

·

Updated

2025-12-10

·

CVE-2024-38213

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Windows (affected versions not specified)
Description The vulnerability is related to a security feature bypass in Microsoft Windows, specifically in the Mark of the Web (MoTW) mechanism. This allows attackers to bypass SmartScreen protections, potentially leading to remote code execution. The issue can be exploited by convincing users to open a specially crafted file. There have been reports of this vulnerability being exploited in the wild since March 2024.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

BDU:2024-06220
CVE-2024-38213
ZDI-24-1209
ZDI-24-1210

Affected Products

Windows