LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-36584: Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 16, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 7, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-36584 to its Known Exploited Vulnerabilities catalog on Nov 16, 2023, with a federal patch deadline of Dec 7, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.

CVE-2023-36584 is a security feature bypass in Microsoft Windows that affects the Mark of the Web (MOTW) mechanism. MOTW is the Windows feature that tags files downloaded from the internet so that other defenses can treat them as untrusted. When this bypass is present, those protections can be undermined, producing a limited loss of integrity and availability of security features. For IT and security teams this matters because MOTW underpins many common controls that reduce risk from email attachments, browser downloads, and other untrusted content; a bypass can let malicious files run with fewer warnings or restrictions than intended. Specifics of impact and fixed builds must be confirmed against the Microsoft vendor advisory.

How it works

The vulnerability is a security feature bypass targeting Mark of the Web handling on Microsoft Windows. In normal operation, Windows attaches MOTW metadata (typically via an alternate data stream) to files that arrive from the internet zone. Downstream components—such as SmartScreen, Office Protected View, and certain script or archive handlers—consult that mark and apply extra scrutiny or restrictions.

An attacker who can deliver a specially crafted file or package may cause the MOTW mark to be lost, ignored, or never applied. The result is that the file is treated as if it originated from a more trusted location, reducing the effectiveness of those security features. The CISA summary describes the outcome as a limited loss of integrity and availability of security features. Exact trigger conditions, file formats, and attack chains are not detailed in the provided facts and must be confirmed against the vendor advisory; defenders should treat any untrusted file delivery path as potentially relevant.

Am I affected? How to find it in your systems

The issue affects Microsoft Windows. Inventory every Windows endpoint and server in scope—workstations, laptops, VDI images, and any servers that process user-downloaded content. Use your asset management, configuration management database, or endpoint management console to list installed Windows editions and build levels, then compare them to the fixed versions listed in the Microsoft advisory for CVE-2023-36584.

Because the CWE is not specified in the facts, treat this as a general MOTW bypass class and validate every finding against the official advisory.

How to remediate

Patch first. Apply the Microsoft security update that addresses CVE-2023-36584 as soon as it has been tested in your environment. Follow the vendor’s installation and reboot guidance exactly; CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be deployed, apply compensating controls that reduce the chance an untrusted file reaches execution without MOTW protections.

These steps lower risk but do not replace the official patch; schedule remediation promptly.

If your data may have been exposed

Actively exploited vulnerabilities can lead to broader compromise and data exposure. Known ransomware use of this CVE is not documented in the provided facts, yet any successful bypass of security features warrants investigation of affected hosts for follow-on activity. Review endpoint and identity logs for unusual execution or lateral movement, isolate systems that show signs of compromise, and follow your incident-response plan. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data to see whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
Added to CISA KEVNov 16, 2023
Federal patch deadlineDec 7, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities