4.4

CVE-2023-24880

Warning

Windows SmartScreen Security Feature Bypass Vulnerability

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows 10 1607 Version < 10.0.14393.5786
MicrosoftWindows 10 1809 Version < 10.0.17763.4131
MicrosoftWindows 10 20h2 Version < 10.0.19042.2728
MicrosoftWindows 10 21h2 Version < 10.0.19044.2728
MicrosoftWindows 10 22h2 Version < 10.0.19045.2728
MicrosoftWindows 11 21h2 Version < 10.0.22000.1696
MicrosoftWindows 11 22h2 Version < 10.0.22000.1413

14.03.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

Vulnerability

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.

Description

Apply updates per vendor instructions.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 90.81% 0.996
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
secure@microsoft.com 4.4 1.8 2.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
nvd@nist.gov 4.4 1.8 2.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.