ZeroHour

CVE-2023-36584

KEVmass

Mark of the Web (MOTW) Security Feature Bypass in Microsoft Windows

CISA: Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability

CVSS 3.1
5.4 medium
EPSS
3%p87
Published
()
KEV added
AI analysis

Microsoft Windows' Mark of the Web (MOTW) feature, which tags files downloaded from the internet so that security checks such as SmartScreen warnings and opening restrictions can apply, fails to correctly apply the mark in affected Windows versions. An attacker can trigger the bypass by delivering a crafted file over the network (typically downloaded or opened by a user), so Windows treats the file as originating from a trusted local source; the CVSS vector confirms network attack surface with required user interaction (AV:N/UI:R). A successful bypass lets a specially crafted application run without the security warnings and restrictions normally applied to internet-originated files, weakening endpoint defenses during malware delivery (per CVSS, integrity and availability are partially impacted with no confidentiality impact from the bypass itself). Any organization or user running Windows 10 (1507, 1809, 21H1, 22H2), Windows 11 (21H2, 22H2), or Windows Server 2008 through 2022 is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-11-16, confirming in-the-wild exploitation, and EPSS assigns a roughly 3.1% probability of exploitation in the next 30 days (87th percentile); no public proof-of-concept is known.

What to do: Apply the November 2023 Windows cumulative security updates for each affected Windows 10, Windows 11, and Windows Server version, consistent with CISA's KEV required action (apply vendor mitigations or discontinue use if updates are unavailable). Prioritize user workstations and any systems where users open downloaded files or documents, since exploitation requires user interaction with a crafted internet-delivered file. Verify patch coverage across all listed Windows branches, as exploitation is confirmed in the wild and the primary gain is defeating MOTW-based warnings to aid malware delivery.

Affected
Microsoft Windows 101507, 1809, 21H1, 22H2
Microsoft Windows 1121H2, 22H2
Microsoft Windows Server2008, 2012, 2016, 2019, 2022
Estimated exposure
mass≈1 billion+ installations (Windows 10/11 desktop installed base plus widely deployed Windows Server versions) — Windows 10 and 11 together run on well over a billion active devices worldwide and the listed Windows Server releases are pervasive in enterprise environments, so the vast majority of Windows fleets are plausibly exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Mark of the Web Security Feature Bypass Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1809, windows 10 21h1, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

In the news