ZeroHour

CVE-2024-21412

KEV ransomwaremass1

CVE-2024-21412: Security Feature Bypass in Microsoft Windows Internet Shortcut Files

CISA: Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability

CVSS 3.1
8.1 high
EPSS
95%p100
Published
()
KEV added
AI analysis

CVE-2024-21412 is a security feature bypass (CWE-693) in how Microsoft Windows handles Internet Shortcut files: a crafted shortcut can make Windows skip the security warning prompt that normally appears before untrusted internet content is opened or downloaded. Triggering it requires user interaction — an attacker must deliver a malicious shortcut file, typically via email or a malicious website, and convince the user to open it, which is reflected in the CVSS vector's UI:R component. An attacker who succeeds gains a bypass of those prompts, making it easier to retrieve and execute malicious remote content with fewer warnings; the DarkGate malware operators used exactly this technique in zero-day campaigns to distribute their loader. Anyone running the affected Windows 10 (1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), Windows Server 2019, or Windows Server 2022 (including 23H2) builds was exposed. The flaw was patched in Microsoft's February 2024 Patch Tuesday release (2024-02-13), the same day CISA added it to the KEV catalog, and it is under active exploitation with known ransomware association and a 95.4% EPSS score.

What to do: Apply the February 2024 Windows cumulative security update (released 2024-02-13) or any later monthly cumulative update to every affected Windows 10, Windows 11, Windows Server 2019, and Windows Server 2022 build, and verify patch levels through your endpoint inventory. Because exploitation requires user interaction, as an interim control flag or block .url/Internet Shortcut attachments at email gateways and remind users not to open shortcuts from untrusted sources. Prioritize internet-facing and shared endpoints given the KEV listing and known ransomware use.

Affected
microsoft Windows 101809, 21H2, 22H2
microsoft Windows 1121H2, 22H2, 23H2
microsoft Windows Server 2019all supported editions
microsoft Windows Server 20222022, 2022 23H2
Estimated exposure
mass≈1 billion Windows 10/11/Server installations potentially affected worldwide (pre-patch installed base) — Windows 10 and 11 run on roughly 1.4 billion active devices per Microsoft, the listed versions cover the dominant Windows 10/11 desktop and Windows Server 2019/2022 installed base, and KEV-listed, ransomware-linked exploitation confirms a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Internet Shortcut Files Security Feature Bypass Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 11 23h2, windows server 2019, windows server 2022, windows server 2022 23h2
Weakness
CWE-693
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

In the news