PT-2024-5548 · Microsoft · Windows
Gothburz
+2
·
Published
2024-08-13
·
Updated
2025-12-10
·
CVE-2024-38213
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows (affected versions not specified)
Description
The vulnerability is related to a security feature bypass in Microsoft Windows, specifically in the Mark of the Web (MoTW) mechanism. This allows attackers to bypass SmartScreen protections, potentially leading to remote code execution. The issue can be exploited by convincing users to open a specially crafted file. There have been reports of this vulnerability being exploited in the wild since March 2024.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows