LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-24880: Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 14, 2023
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 4, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-24880 to its Known Exploited Vulnerabilities catalog on Mar 14, 2023, with a federal patch deadline of Apr 4, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.

CVE-2023-24880 is a security feature bypass in Microsoft Windows SmartScreen. It can let an attacker evade Mark of the Web (MOTW) protections by delivering a specially crafted malicious file. Because MOTW is a common Windows defense that flags files from untrusted sources and triggers extra scrutiny or blocking, a bypass of this kind matters for endpoint security. CISA notes known ransomware use of this vulnerability, so organizations should treat it as a priority for Windows fleets.

Public detail is limited to the class of issue and the high-level impact described by CISA. Exact affected builds, exploit mechanics, and scoring must be confirmed against the Microsoft vendor advisory.

How it works

The underlying weakness is CWE-863 (Incorrect Authorization). In this case, SmartScreen fails to correctly enforce authorization checks tied to Mark of the Web. MOTW is an alternate data stream Windows applies to files downloaded from the internet or other untrusted origins; SmartScreen and related components use it to decide whether to warn the user, block execution, or apply additional policy.

An attacker abuses the flaw by crafting a malicious file that causes SmartScreen to skip or mis-handle the MOTW evaluation. The result is that a file which should have been treated as untrusted may run with fewer warnings or restrictions. No further exploit specifics are provided in the available facts; defenders should assume a specially crafted file is the delivery vehicle and should not invent payload details. Confirm the precise conditions and any prerequisites in the vendor advisory.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that use SmartScreen. SmartScreen is present on modern Windows client and server editions that handle user-downloaded content, email attachments, or files from removable or network sources. Inventory every Windows endpoint and server that processes untrusted files.

How to remediate

Patch first. Apply the Microsoft updates for CVE-2023-24880 exactly as directed in the vendor advisory. CISA’s required action is to apply updates per vendor instructions; treat that as the primary remediation step.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls that limit the usefulness of a MOTW bypass.

These measures lower risk but do not replace the vendor patch. Schedule the update as soon as operational constraints allow.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, frequently lead to breaches. If you suspect this CVE was used against your environment, follow your incident response plan: isolate affected hosts, preserve forensic evidence, and assess for ransomware or data theft. Independently, you can run a free exposure scan of your email address against known breach data to check whether credentials or personal information associated with your accounts have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-863
Added to CISA KEVMar 14, 2023
Federal patch deadlineApr 4, 2023
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities