Skip to content
COOEY

EXPOSURES › CVE-2024-38213

CVE-2024-38213

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-08-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-38213 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildsupply-chain

Microsoft Windows SmartScreen bypass allows attackers to evade a key security feature via malicious files.

This vulnerability enables attackers to bypass Windows SmartScreen, a critical user experience security feature, by delivering malicious files that circumvent its protections. For DIB organizations, this increases exposure to malware and ransomware by undermining a primary defense layer in the Windows supply chain. Immediate patching and SmartScreen configuration hardening are required to mitigate this risk.

Shame score — A known bypass vulnerability in a widely deployed security feature that was actively exploited but did not involve vendor negligence or default credentials.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience via a malicious file.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized