EXPOSURES › CVE-2024-38213
CVE-2024-38213
HIGH ⌖ ON CISA KEV · EXPLOITEDMicrosoft Windows SmartScreen bypass allows attackers to evade a key security feature via malicious files.
This vulnerability enables attackers to bypass Windows SmartScreen, a critical user experience security feature, by delivering malicious files that circumvent its protections. For DIB organizations, this increases exposure to malware and ransomware by undermining a primary defense layer in the Windows supply chain. Immediate patching and SmartScreen configuration hardening are required to mitigate this risk.
Shame score — A known bypass vulnerability in a widely deployed security feature that was actively exploited but did not involve vendor negligence or default credentials.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience via a malicious file.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |