← back
CVE-2023-36025

Windows SmartScreen Security Feature Bypass Vulnerability

CVSS 8.8 HIGHEPSS 88.2%● KEV
In short

Windows SmartScreen, a security feature that warns users about potentially dangerous files and websites, can be bypassed by attackers. This means malicious files could be downloaded and executed without triggering the security warning that normally protects users.

Technical detail

This vulnerability allows an attacker to bypass the SmartScreen reputation check through a crafted file or URI parameter manipulation, enabling delivery of malware without triggering security alerts. Exploitation requires user interaction (file download or opening a link) but can result in arbitrary code execution due to disabled security warnings.

Summary generated and translated by AI from the official description.
Windows SmartScreen Security Feature Bypass Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →