ZeroHour

CVE-2023-36025

KEVmass1

Windows SmartScreen Bypass (CVE-2023-36025) Exploited via Crafted Shortcut Files

CISA: Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

CVSS 3.1
8.8 high
EPSS
88%p100
Published
()
KEV added
AI analysis

CVE-2023-36025 is a security feature bypass in Windows SmartScreen in which a specially crafted file — exploited in the wild using Internet Shortcut (.url) files — evades the Mark-of-the-Web warning SmartScreen normally displays for content downloaded from the internet. The flaw is network-reachable and requires no authentication, but user interaction is required: it triggers when a user clicks the crafted file delivered via phishing email, chat, or a web download. By bypassing the SmartScreen prompt, the attacker removes a key user-facing defense that would otherwise flag or warn about the file, which facilitated delivery of malware in the observed DarkGate and Mispadu campaigns. Any unpatched Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server 2008/2012/2016/2019 system is affected, which at the time of disclosure effectively meant the entire supported Windows installed base. It is confirmed exploited in the wild: CISA added it to the KEV catalog on 2023-11-14, EPSS scores 30-day exploitation probability at 88.1% (100th percentile), though no public PoC is known.

What to do: Apply Microsoft's November 2023 cumulative Windows security updates (the release containing the fix) on all affected Windows 10/11 and Windows Server systems; no configuration-based workaround is widely documented, so patching is the primary mitigation. Until patched, treat unexpected Internet Shortcut (.url) files arriving via email or chat with extra suspicion, since they can execute without the usual SmartScreen warning, and hunt for DarkGate/Mispadu indicators. Given the KEV listing and 88.1% EPSS, prioritize this fix in the current patch cycle; ransomware-associated use is reported as unknown.

Affected
microsoft Windows 101507 (builds prior to the November 2023 security updates)
microsoft Windows 101607 (builds prior to the November 2023 security updates)
microsoft Windows 101809 (builds prior to the November 2023 security updates)
microsoft Windows 1021H2 (builds prior to the November 2023 security updates)
microsoft Windows 1022H2 (builds prior to the November 2023 security updates)
microsoft Windows 1121H2 (builds prior to the November 2023 security updates)
microsoft Windows 1122H2 (builds prior to the November 2023 security updates)
microsoft Windows 1123H2 (builds prior to the November 2023 security updates)
microsoft Windows Server2008 (builds prior to the November 2023 security updates)
microsoft Windows Server2012 (builds prior to the November 2023 security updates)
microsoft Windows Server2016 (builds prior to the November 2023 security updates)
microsoft Windows Server2019 (builds prior to the November 2023 security updates)
Estimated exposure
mass>1 billion endpoints (effectively the entire supported Windows 10/11/Server installed base at the time of disclosure) — Every supported Windows 10, Windows 11, and Windows Server build at disclosure was in scope, and Windows 10/11 together run on an estimated ~1-1.4 billion active devices worldwide, so exposure is fleet-wide across the mass-market Windows…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows SmartScreen Security Feature Bypass Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 11 23h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news