LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-21412: Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 13, 2024
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Mar 5, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-21412 to its Known Exploited Vulnerabilities catalog on Feb 13, 2024, with a federal patch deadline of Mar 5, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass.

CVE-2024-21412 is a security feature bypass vulnerability in Microsoft Windows that affects Internet Shortcut Files. It allows an attacker to circumvent a protective control that Windows normally applies when handling these files. Because the issue is known to be used in ransomware activity, organizations that run Windows should treat it as a priority for inventory, patching, and monitoring.

Public technical detail is limited to the high-level description provided by CISA and the vendor; exact mechanics, affected builds, and scoring must be confirmed against the official Microsoft advisory for this CVE.

How it works

The vulnerability is classified under CWE-693 (Protection Mechanism Failure). Internet Shortcut Files are a Windows file type commonly used to open web resources or local paths. A security feature that is supposed to restrict or warn on certain shortcut behaviors can be bypassed, so the intended protection does not take effect.

An attacker who can deliver or place a crafted Internet Shortcut File on a system may cause Windows to process it without the normal safeguard. The CISA summary describes the issue only as an unspecified security feature bypass; no further exploit steps or payloads are provided here. Defenders should assume that successful abuse can lead to further code execution or user interaction that the bypassed control was meant to prevent, and they must rely on the vendor advisory for any precise trigger conditions.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows. Internet Shortcut Files can appear on any Windows endpoint or server where users open .url files, receive them via email or file shares, or where applications generate shortcuts. Typical locations include user desktops, Downloads folders, temporary directories, and network shares.

How to remediate

Apply the vendor update that Microsoft released for CVE-2024-21412. Follow the installation and reboot guidance in the official advisory. After patching, verify the update is present with your patch-management console or by checking the relevant Windows update history.

CISA’s required action is to apply mitigations per vendor instructions or to discontinue use of the product if mitigations are unavailable. Confirm that your chosen remediation path matches the current Microsoft guidance.

If you can't patch immediately

Until the official update can be installed, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited vulnerabilities of this type have been observed in ransomware campaigns and can lead to broader compromise. If you have evidence that a crafted Internet Shortcut File was opened on an unpatched system, assume the possibility of follow-on access and begin containment, forensic collection, and credential-reset procedures as appropriate. Separately, you can run a free exposure scan of your email addresses against known breach data sets to determine whether any of your accounts already appear in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-693
Added to CISA KEVFeb 13, 2024
Federal patch deadlineMar 5, 2024
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities