CVE-2023-36584
KEVmassMark of the Web (MOTW) Security Feature Bypass in Microsoft Windows
CISA: Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
Microsoft Windows' Mark of the Web (MOTW) feature, which tags files downloaded from the internet so that security checks such as SmartScreen warnings and opening restrictions can apply, fails to correctly apply the mark in affected Windows versions. An attacker can trigger the bypass by delivering a crafted file over the network (typically downloaded or opened by a user), so Windows treats the file as originating from a trusted local source; the CVSS vector confirms network attack surface with required user interaction (AV:N/UI:R). A successful bypass lets a specially crafted application run without the security warnings and restrictions normally applied to internet-originated files, weakening endpoint defenses during malware delivery (per CVSS, integrity and availability are partially impacted with no confidentiality impact from the bypass itself). Any organization or user running Windows 10 (1507, 1809, 21H1, 22H2), Windows 11 (21H2, 22H2), or Windows Server 2008 through 2022 is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-11-16, confirming in-the-wild exploitation, and EPSS assigns a roughly 3.1% probability of exploitation in the next 30 days (87th percentile); no public proof-of-concept is known.
What to do: Apply the November 2023 Windows cumulative security updates for each affected Windows 10, Windows 11, and Windows Server version, consistent with CISA's KEV required action (apply vendor mitigations or discontinue use if updates are unavailable). Prioritize user workstations and any systems where users open downloaded files or documents, since exploitation requires user interaction with a crafted internet-delivered file. Verify patch coverage across all listed Windows branches, as exploitation is confirmed in the wild and the primary gain is defeating MOTW-based warnings to aid malware delivery.
| Microsoft Windows 10 | 1507, 1809, 21H1, 22H2 |
| Microsoft Windows 11 | 21H2, 22H2 |
| Microsoft Windows Server | 2008, 2012, 2016, 2019, 2022 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows Mark of the Web Security Feature Bypass Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1809, windows 10 21h1, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L