LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-21351: Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 13, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 5, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-21351 to its Known Exploited Vulnerabilities catalog on Feb 13, 2024, with a federal patch deadline of Mar 5, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience and inject code to potentially gain code execution…

CVE-2024-21351 is a security feature bypass in Microsoft Windows SmartScreen. It lets an attacker sidestep the SmartScreen user experience and inject code that can lead to code execution. Successful abuse could result in data exposure, reduced system availability, or both. Because SmartScreen is a common Windows defense against untrusted files and downloads, the issue matters for any organization running Windows endpoints or servers that rely on it.

Defenders should treat this as a high-priority item for inventory and patching. Confirm exact impact, fixed builds, and deployment guidance against the official Microsoft advisory rather than relying on secondary summaries.

How it works

The vulnerability is classified under CWE-94, improper control of code generation (code injection). SmartScreen is designed to evaluate files and present warnings or blocks before untrusted content runs. The flaw allows an attacker to bypass that user-facing protection and inject code, creating a path to potential code execution on the target system.

In practice, an attacker would need to deliver a crafted file or content that triggers the bypass. Once the SmartScreen experience is circumvented, the injected code can execute with the privileges of the user or process that opened the content. The CISA summary notes this can lead to data exposure or availability impact. No further exploit mechanics, payloads, or prerequisites are detailed in the available facts; teams must consult the vendor advisory for any additional technical constraints or attack vectors.

Am I affected? How to find it in your systems

The issue affects Microsoft Windows systems that include the SmartScreen security feature. SmartScreen is present by default on modern Windows client and server editions used as endpoints, jump hosts, or application servers. Inventory all Windows devices in your estate—workstations, laptops, virtual desktops, and servers—using asset management tools, Microsoft Endpoint Configuration Manager, Intune, or equivalent discovery methods.

For signs of exploitation, examine endpoint detection and response (EDR) telemetry, Windows event logs related to SmartScreen decisions, process creation events following file downloads or email attachments, and any anomalous code execution from unexpected locations. Because public detail on specific indicators is limited, treat unexplained SmartScreen bypasses or subsequent code injection as suspicious and investigate promptly.

How to remediate

Apply the vendor-supplied security update for Microsoft Windows that remediates CVE-2024-21351 as the primary action. Follow Microsoft’s published instructions for deployment, testing, and reboot requirements. CISA directs organizations to apply mitigations per vendor instructions or to discontinue use of the product if mitigations are unavailable.

After patching, re-enable or harden SmartScreen where policy allows, ensure automatic updates are functioning, and verify the update is present across the estate via compliance reporting. For this class of security-feature-bypass and code-injection weakness, also review least-privilege settings so that even successful injection runs with minimal rights, and keep application control or attack-surface-reduction rules active to limit what injected code can do.

If you can't patch immediately

Until the update can be deployed, reduce risk with compensating controls. Segment high-value systems so that endpoints handling untrusted files cannot freely reach critical servers or data stores. Apply virtual patching or web-application-firewall rules if the attack path involves network-delivered content, though SmartScreen is primarily a local Windows feature. Disable or tightly control the features that allow untrusted files to reach users (for example, restrict email attachment types or browser download behaviors) where business needs permit.

These steps do not eliminate the vulnerability; they only buy time until the official patch is applied. Confirm any temporary configuration changes against Microsoft guidance so they do not introduce new gaps.

If your data may have been exposed

Actively exploited security-feature-bypass and code-execution vulnerabilities can lead to unauthorized access and data exposure. Known ransomware use of this CVE is not documented in the available facts. If you suspect compromise, follow your incident-response plan: isolate affected hosts, preserve logs and memory, and hunt for lateral movement or data exfiltration. Organizations and individuals can also run a free exposure scan of their email addresses against known breach data sets to determine whether credentials or personal information have already appeared in public breach collections, then force password resets and enable multi-factor authentication where accounts are confirmed exposed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-94
Added to CISA KEVFeb 13, 2024
Federal patch deadlineMar 5, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities