ZeroHour

CVE-2024-29988

KEVmass1

Mark of the Web Security Feature Bypass in Microsoft SmartScreen Prompt

CISA: Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability

CVSS 3.1
8.8 high
EPSS
45%p99
Published
()
KEV added
AI analysis

CVE-2024-29988 is a security feature bypass in Microsoft SmartScreen Prompt that allows an attacker to defeat the Mark of the Web (MotW) mechanism, which normally flags internet-downloaded files so SmartScreen shows a warning before they run. An attacker triggers it by delivering a crafted file that Windows processes without the expected SmartScreen prompt, often as part of an exploit chain with CVE-2023-38831 (WinRAR) or the related SmartScreen bypass CVE-2024-21412. Successful exploitation strips away a key browser/download defense layer, letting a malicious file execute with no user warning. Any Windows system that relies on SmartScreen to vet internet-delivered content is affected; the available data does not specify affected version ranges. The flaw is confirmed to be exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2024-04-30 — and EPSS estimates a 45.2% chance of exploitation in the next 30 days (99th percentile), though no public PoC is known.

What to do: Apply Microsoft's update for CVE-2024-29988 as soon as possible via Windows Update, per CISA's KEV required action to apply vendor mitigations; verify patch status across Windows endpoints. Until patched, scrutinize internet-delivered archives and installers, and ensure the chain components are also remediated — update WinRAR for CVE-2023-38831 and patch the related SmartScreen bypass CVE-2024-21412.

Affected
Microsoft SmartScreen Prompt
Estimated exposure
masshundreds of millions of Windows devices (SmartScreen is built into and enabled by default on Windows 10/11) — SmartScreen is a default component of essentially all modern Windows installations, and Windows is estimated to run on well over a billion devices, so the realistic exposure base is in the hundreds of millions of systems.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SmartScreen Prompt Security Feature Bypass Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft SmartScreen Prompt
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 11 23h2, windows server 2019, windows server 2022, windows server 2022 23h2
Weakness
CWE-693
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news