CERT-In Vulnerability Note
CIVN-2024-0048
Security Feature Bypass Vulnerability in Windows SmartScreen
Original Issue Date:February 15, 2024
Severity Rating: HIGH
Software Affected
- Windows 11 Version 23H2 for x64-based Systems
- Windows 11 Version 23H2 for ARM64-based Systems
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 1809 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 10 Version 21H2 for 32-bit Systems
- Windows 10 Version 21H2 for ARM64-based Systems
- Windows 10 Version 21H2 for x64-based Systems
- Windows 11 Version 22H2 for ARM64-based Systems
- Windows 11 Version 22H2 for x64-based Systems
- Windows 10 Version 22H2 for x64-based Systems
- Windows 10 Version 22H2 for ARM64-based Systems
- Windows 10 Version 22H2 for 32-bit Systems
- Windows 10 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 Version 1607 for x64-based Systems
- Windows Server 2016
- Windows Server 2019
- Windows Server 2022
Overview
A vulnerability has been reported in Windows SmartScreen, which could allow a remote attacker to bypass SmartScreen security checks.
Description
This vulnerability exists in Windows SmartScreen due to improper input validation while handling files downloaded from the Internet. An attacker could exploit this vulnerability by sending a malicious file and convincing the user to open it. Successful exploitation of this vulnerability could allow an attacker to bypass SmartScreen security checks.
Note: This vulnerability (CVE-2024-21351) is being exploited in the wild.
Solution
Apply appropriate security updates as mentioned in the below link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21351
Vendor Information
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21351
References
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21351
Bleeping Computer
https://www.bleepingcomputer.com/news/microsoft/microsoft-february-2024-patch-tuesday-fixes-2-zero-days-73-flaws/
CVE Name
CVE-2024-21351
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|