LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-32049: Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 11, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 1, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-32049 to its Known Exploited Vulnerabilities catalog on Jul 11, 2023, with a federal patch deadline of Aug 1, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows Defender SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the Open File - Security Warning prompt.

CVE-2023-32049 is a security feature bypass in Microsoft Windows Defender SmartScreen. It lets an attacker bypass the Open File - Security Warning prompt that normally appears when a user opens a downloaded or untrusted file. This matters because that prompt is a last-line warning that can stop users from running malicious content; removing it lowers the barrier for social-engineering or drive-by delivery of malware on Windows endpoints.

Defenders should treat the issue as a client-side warning bypass rather than a remote code-execution flaw. Specifics such as exact affected builds, attack vectors, and severity must be confirmed against the Microsoft advisory.

How it works

The vulnerability is a security-feature bypass in Windows Defender SmartScreen. SmartScreen normally evaluates files and displays the Open File - Security Warning dialog for content that lacks a trusted reputation or digital signature. An attacker who can deliver a crafted file or manipulate the conditions under which SmartScreen evaluates it can cause that dialog to be skipped. The user then sees no warning and may open or execute the file under the assumption that it is safe.

Because the CWE is not specified in public summaries, treat the flaw as a classic security-control bypass: the protective UI and reputation check are circumvented while the rest of the operating system continues to run normally. No public details describe the precise trigger, so do not assume particular file types, protocols, or user actions beyond what the vendor advisory states.

Am I affected? How to find it in your systems

The issue affects Microsoft Windows systems that use Windows Defender SmartScreen. SmartScreen is present by default on modern Windows client and server editions that include Windows Defender or Microsoft Defender Antivirus components.

If SmartScreen is disabled by policy, the system is not protected by the feature at all and should be treated as higher risk for this class of attack.

How to remediate

Apply the Microsoft security update that resolves CVE-2023-32049 as soon as it is available for your Windows builds. Follow the vendor’s instructions exactly; CISA guidance is to apply updates per vendor instructions or discontinue use of the product if updates cannot be obtained.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls focused on the bypass class.

If your data may have been exposed

Actively exploited security-feature bypasses can lead to malware installation and subsequent data theft. Public information does not document ransomware use of this CVE, but any successful bypass should be investigated as a potential compromise. Review endpoint telemetry for post-exploitation activity, isolate affected hosts, and rotate credentials that may have been exposed. You can also run a free exposure scan of your email addresses against known breach data sets to check whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
Added to CISA KEVJul 11, 2023
Federal patch deadlineAug 1, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities