CVE-2023-36025
KEVmass1Windows SmartScreen Bypass (CVE-2023-36025) Exploited via Crafted Shortcut Files
CISA: Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
CVE-2023-36025 is a security feature bypass in Windows SmartScreen in which a specially crafted file — exploited in the wild using Internet Shortcut (.url) files — evades the Mark-of-the-Web warning SmartScreen normally displays for content downloaded from the internet. The flaw is network-reachable and requires no authentication, but user interaction is required: it triggers when a user clicks the crafted file delivered via phishing email, chat, or a web download. By bypassing the SmartScreen prompt, the attacker removes a key user-facing defense that would otherwise flag or warn about the file, which facilitated delivery of malware in the observed DarkGate and Mispadu campaigns. Any unpatched Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server 2008/2012/2016/2019 system is affected, which at the time of disclosure effectively meant the entire supported Windows installed base. It is confirmed exploited in the wild: CISA added it to the KEV catalog on 2023-11-14, EPSS scores 30-day exploitation probability at 88.1% (100th percentile), though no public PoC is known.
What to do: Apply Microsoft's November 2023 cumulative Windows security updates (the release containing the fix) on all affected Windows 10/11 and Windows Server systems; no configuration-based workaround is widely documented, so patching is the primary mitigation. Until patched, treat unexpected Internet Shortcut (.url) files arriving via email or chat with extra suspicion, since they can execute without the usual SmartScreen warning, and hunt for DarkGate/Mispadu indicators. Given the KEV listing and 88.1% EPSS, prioritize this fix in the current patch cycle; ransomware-associated use is reported as unknown.
| microsoft Windows 10 | 1507 (builds prior to the November 2023 security updates) |
| microsoft Windows 10 | 1607 (builds prior to the November 2023 security updates) |
| microsoft Windows 10 | 1809 (builds prior to the November 2023 security updates) |
| microsoft Windows 10 | 21H2 (builds prior to the November 2023 security updates) |
| microsoft Windows 10 | 22H2 (builds prior to the November 2023 security updates) |
| microsoft Windows 11 | 21H2 (builds prior to the November 2023 security updates) |
| microsoft Windows 11 | 22H2 (builds prior to the November 2023 security updates) |
| microsoft Windows 11 | 23H2 (builds prior to the November 2023 security updates) |
| microsoft Windows Server | 2008 (builds prior to the November 2023 security updates) |
| microsoft Windows Server | 2012 (builds prior to the November 2023 security updates) |
| microsoft Windows Server | 2016 (builds prior to the November 2023 security updates) |
| microsoft Windows Server | 2019 (builds prior to the November 2023 security updates) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows SmartScreen Security Feature Bypass Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 11 23h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H