CVE-2024-38213 - Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Project:Microsoft
Product:Windows
Date Added:2024-08-13Due Date:2024-09-03
Vulnerability Name
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Description
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience via a malicious file.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38213
https://nvd.nist.gov/vuln/detail/CVE-2024-38213
Related News Articles
CERT-UA Warns of UAC-0173 Attacks Deploying DCRat to Compromise Ukrainian NotariesFebruary 26, 2025
7-Zip fixes bug that bypasses Windows MoTW security warnings, patch nowJanuary 22, 2025
Microsoft Issues Patches for 90 Flaws, Including 10 Critical Zero-DaysAugust 14, 2024
Microsoft Issues Patches for 90 Flaws, Including 10 Critical Zero-Day ExploitsAugust 14, 2024
New Windows SmartScreen bypass exploited as zero-day since MarchAugust 14, 2024