by @jakaba
20 Dec 2023
#cve_analysis
Windows SmartScreen Security Feature bypass (CVE-2023-24880)
by @jakaba
20 Dec 2023
Windows SmartScreen Security Feature bypass (CVE-2023-24880)
OS
W12
Windows 11 21H2Microsoft
10.0.22000.3019.*
10.0.22000.3147.*
10.0.22000.2777.*
10.0.22000.2777.*
10.0.22000.3260.*
10.0.22000.3260.*
10.0.22000.2710.*
10.0.22000.2899.*
10.0.22000.2899.*
22000.2899.*
show all related OS
W12
Windows 11 22H2Microsoft
10.0.22621.6060.*
10.0.22621.6060.*
10.0.22621.5909.*
10.0.22621.5909.*
10.0.22621.5900.*
10.0.22621.5900.*
10.0.22621.5768.*
10.0.22621.5768.*
10.0.22621.5624.*
10.0.22621.5624.*
W12
Windows 10 22H2Microsoft
10.0.19045.6691.*
10.0.19045.6691.*
10.0.19045.6691.*
10.0.19045.4529.*
10.0.19045.6809.*
10.0.19045.6809.*
10.0.19045.6809.*
10.0.19045.6575.*
10.0.19045.6575.*
10.0.19045.6575.*
W12
Windows 10 21H2Microsoft
10.0.19044.6691.*
10.0.19044.6691.*
10.0.19044.6691.*
10.0.19044.6809.*
10.0.19044.6809.*
10.0.19044.6809.*
10.0.19044.4529.*
10.0.19044.6575.*
10.0.19044.6575.*
10.0.19044.6575.*
W11
Windows 10 1607Microsoft
10.0.14393.8688.*
10.0.14393.8688.*
10.0.14393.8783.*
10.0.14393.8783.*
10.0.14393.8594.*
10.0.14393.8594.*
10.0.14393.8519.*
10.0.14393.8519.*
10.0.14393.8422.*
10.0.14393.8422.*
W11
Windows 10 1809Microsoft
10.0.17763.8146.*
10.0.17763.8146.*
10.0.17763.8276.*
10.0.17763.8276.*
10.0.17763.8027.*
10.0.17763.8027.*
10.0.17763.7919.*
10.0.17763.7919.*
10.0.17763.7792.*
10.0.17763.7792.*
Windows Server 2022Microsoft
10.0.20348.4467.*
10.0.20348.4467.*
10.0.20348.4467.*
10.0.20348.4529.*
10.0.20348.4529.*
10.0.20348.4529.*
10.0.20348.4648.*
10.0.20348.4648.*
10.0.20348.4648.*
10.0.20348.4648.*
Windows Server 2019Microsoft
10.0.17763.8146.*
10.0.17763.8276.*
10.0.17763.8027.*
10.0.17763.7922.*
10.0.17763.7919.*
10.0.17763.7792.*
10.0.17763.7783.*
10.0.17763.7678.*
10.0.17763.7558.*
10.0.17763.7136.*
Windows Server 2016Microsoft
10.0.14393.8688.*
10.0.14393.8783.*
10.0.14393.8594.*
10.0.14393.8524.*
10.0.14393.8519.*
10.0.14393.8519.*
10.0.14393.8422.*
10.0.14393.8416.*
10.0.14393.8330.*
10.0.14393.8246.*
W12
Windows 10 20H2Microsoft
10.0.19042.2788.*
10.0.19042.2788.*
10.0.19042.2788.*
10.0.19042.2673.*
10.0.19042.2673.*
10.0.19042.2673.*
10.0.19042.2546.*
10.0.19042.2546.*
10.0.19042.2546.*
10.0.19042.2364.*
Screenshots from the blog posts
Summary
Microsoft Windows SmartScreen contained a security feature bypass vulnerability that could enable an attacker to circumvent Mark of the Web (MOTW) defenses through a specially crafted malicious file.
Description
Comments (0)