by @leo.granda
22 Mar 2024

Bypassing Defender SmartScreen & Outlook Protected View Protocol

by @leo.granda
22 Mar 2024

Bypassing Defender SmartScreen & Outlook Protected View Protocol

CVEs

8.1 High Severity
9.8 Critical Severity

OS

10.0.25398.2330.*
10.0.25398.2207.*
10.0.25398.2149.*
10.0.25398.2149.*
10.0.25398.2274.*
10.0.25398.2025.*
10.0.25398.2092.*
10.0.25398.1965.*
10.0.25398.1913.*
10.0.25398.1916.*
10.0.20348.3695.*
10.0.20348.3695.*
10.0.20348.3695.*
10.0.20348.4893.*
10.0.20348.4893.*
10.0.20348.4893.*
10.0.20348.4773.*
10.0.20348.4773.*
10.0.20348.4773.*
10.0.20348.4776.*
10.0.17763.3772.*
10.0.17763.5579.*
10.0.17763.8389.*
10.0.17763.8755.*
10.0.17763.7683.*
10.0.17763.7240.*
10.0.17763.8281.*
10.0.17763.8647.*
10.0.17763.7249.*
10.0.17763.7322.*
W12
10.0.22631.6649.*
10.0.22631.6649.*
10.0.22631.6783.*
10.0.22631.6783.*
10.0.22631.7079.*
10.0.22631.7079.*
10.0.22631.6936.*
10.0.22631.6936.*
10.0.22631.6345.*
10.0.22631.6345.*
W12
10.0.22000.3019.*
10.0.22000.3147.*
10.0.22000.2777.*
10.0.22000.2777.*
10.0.22000.3260.*
10.0.22000.3260.*
10.0.22000.2710.*
10.0.22000.2899.*
10.0.22000.2899.*
22000.2899.*
W12
10.0.22621.6060.*
10.0.22621.6060.*
10.0.22621.5909.*
10.0.22621.5909.*
10.0.22621.5900.*
10.0.22621.5900.*
10.0.22621.5768.*
10.0.22621.5768.*
10.0.22621.5624.*
10.0.22621.5624.*
W12
10.0.19045.6937.*
10.0.19045.6937.*
10.0.19045.6937.*
10.0.19045.7058.*
10.0.19045.7058.*
10.0.19045.7058.*
10.0.19045.7291.*
10.0.19045.7291.*
10.0.19045.7291.*
10.0.19045.7184.*
W12
10.0.19044.7291.*
10.0.19044.7291.*
10.0.19044.7291.*
10.0.19044.7184.*
10.0.19044.7184.*
10.0.19044.7184.*
10.0.19044.7058.*
10.0.19044.7058.*
10.0.19044.7058.*
10.0.19044.6937.*
W11
10.0.17763.8389.*
10.0.17763.8389.*
10.0.17763.8755.*
10.0.17763.8755.*
10.0.17763.8644.*
10.0.17763.8644.*
10.0.17763.8511.*
10.0.17763.8511.*
10.0.17763.8146.*
10.0.17763.8146.*

Apps

2024.*
2021.*
365 Apps
365 AppsMicrosoft
16.0.19127.20314.*
2401.17231.20236.*
116.0.17231.20194.*
16.0.17425.20070.*
16.0.17328.20184.*
16.0.17328.20162.*
16.0.17328.20068.*
16.0.17231.20236.*
16.0.17231.20194.*
16.0.17126.20132.*
Office
OfficeMicrosoft
16.0.20210.20000.*
16.0.19822.20288.*
16.0.20131.20044.*
16.0.19929.20220.*
16.0.20208.20000.*
16.0.19725.20382.*
16.0.17303.20000.*
16.0.19127.20678.*
16.0.20207.20000.*
16.0.14334.20756.*

Screenshots from the blog posts

images/clu2nciod2xh21jk47m8mc74l.pngimages/clu2nciod2xh21jk47m8mc74l.png

Summary

CVE-2024-21412 and CVE-2024-21413 represent significant cybersecurity threats. The exploitation of these vulnerabilities underscores the importance of proactive measures to safeguard against emerging threats. By adopting a multilayered security approach, staying vigilant, and implementing best practices, organizations can mitigate the risks posed by these and future vulnerabilities.

Description

users/photos/cl16zs42l01qe0knx382g7y3m.jpg

@leo.granda

18 posts

Total vcoins

50

Badges

badges/images/cl1xi65zx02el0jms239bekpv.png

Malware Researcher

badges/images/cl1xi6pcn02et0jms48zfg0ns.png

Early-bird

badges/images/clktw3w8b0psc1inaam75d4oc.png

Vulnerability Researcher

Social media links

Comments (1)