← back
CVE-2024-38217

Windows Mark of the Web Security Feature Bypass Vulnerability

CVSS 5.4 MEDIUMEPSS 9.8%● KEVCWE-693
In short

A security feature in Windows that warns users about potentially dangerous files downloaded from the internet can be bypassed, allowing malicious files to run without the expected warning.

Technical detail

This vulnerability exploits improper validation of the Mark of the Web (MOTW) stream attribute in Windows, allowing an attacker to craft specially formatted files that bypass the security prompt mechanism designed to protect against execution of untrusted downloaded content. The attack requires user interaction to execute the file, but circumvents the warning dialog that would normally alert users to the risk.

Summary generated and translated by AI from the official description.
Windows Mark of the Web Security Feature Bypass Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L/E:F/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →