ZeroHour

CVE-2023-32049

KEVmass

Windows SmartScreen Security Feature Bypass Exploited in the Wild (CVE-2023-32049)

CISA: Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability

CVSS 3.1
8.8 high
EPSS
4%p90
Published
()
KEV added
AI analysis

CVE-2023-32049 is a security feature bypass in Microsoft Windows Defender SmartScreen, the mechanism that warns users before they run downloaded or untrusted content; specially crafted content delivered over the network causes SmartScreen to skip that warning when a user opens it. The flaw requires user interaction (CVSS vector AV:N/AC:L/UI:R), so attackers must lure a victim into clicking or opening the crafted URL or file, and in exchange they gain the ability to run content without the expected SmartScreen prompt, typically as a link in a chain that delivers malware or establishes initial access. All users of Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2), and Windows Server 2016/2019/2022 are affected. The flaw was fixed in Microsoft's July 2023 Patch Tuesday batch (132 vulnerabilities, six under active attack) and was added to CISA's Known Exploited Vulnerabilities catalog on 2023-07-11, confirming in-the-wild exploitation; no public proof-of-concept is known and ransomware use is unknown.

What to do: Apply Microsoft's July 2023 (or later) cumulative Windows security updates on every affected Windows 10, Windows 11, and Windows Server release, per the vendor instructions and CISA KEV required action. After patching, verify SmartScreen and Mark-of-the-Web warning behavior remain enabled and intact, and prioritize fleet-wide rollout given confirmed in-the-wild exploitation; treat unpatched users as susceptible to warning-free delivery of malicious files and links.

Affected
Microsoft Windows 101607, 1809, 21H2, 22H2
Microsoft Windows 1121H2, 22H2
Microsoft Windows Server2016, 2019, 2022
Estimated exposure
masshundreds of millions of endpoints and servers (the affected Windows 10/11 and Server releases make up the large majority of the supported Windows installed… — Windows 10/11 have an installed base of over a billion devices with these feature versions covering most enterprise and consumer fleets, and Windows Server 2016-2022 are ubiquitous in corporate data centers; this is an estimate from public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows SmartScreen Security Feature Bypass Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows server 2016, windows server 2019, windows server 2022
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news