ZeroHour

CVE-2024-38217

KEV PoC mass

Mark of the Web (MOTW) Security Feature Bypass in Microsoft Windows - Actively Exploited

CISA: Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability

CVSS 3.1
5.4 medium
EPSS
10%p95
Published
()
KEV added
AI analysis

CVE-2024-38217 is a protection mechanism failure (CWE-693) in Microsoft Windows' Mark of the Web (MOTW) feature, which tags files downloaded from the internet so Windows can apply security warnings. An attacker can craft a file whose MOTW marking fails or is not correctly applied; when a user is tricked into opening or saving that file (user interaction is required per the CVSS vector), Windows' MOTW-based protections, such as SmartScreen/Smart App Control prompts, are bypassed. The scored impact is limited to integrity and availability (CVSS 3.1: 5.4, medium), but the bypass can make malicious files appear trustworthy to users. All of the listed Windows 10, Windows 11, and Windows Server releases are affected. The flaw was actively exploited in the wild at the time of September 2024 Patch Tuesday, was added to CISA's KEV on 2024-09-10, and a public proof-of-concept demonstrating a bypass of Smart App Control has been published by Elastic Security Labs; EPSS estimates a 10% probability of exploitation in the next 30 days (95th percentile).

What to do: Apply Microsoft's September 2024 (or later) Windows cumulative security updates across all listed Windows 10, Windows 11, and Windows Server releases, and verify the fix actually took effect, since reporting indicates a Microsoft code defect left some systems without an effective earlier fix. Until patched, exercise caution opening or saving files obtained from the internet, as exploitation requires user interaction. Organizations subject to CISA KEV requirements must apply the vendor mitigations or discontinue use of affected products per the KEV directive.

Affected
Microsoft Windows 101507, 1607, 1809, 21H2, 22H2
Microsoft Windows 1121H2, 22H2, 23H2, 24H2
Microsoft Windows Server2008, 2012, 2016
Estimated exposure
masshundreds of millions to ~1 billion Windows devices (essentially the entire Windows 10/11 and Windows Server install base) — Windows 10 and 11 are installed on well over a billion devices worldwide and the affected release list spans effectively all supported Windows client and server versions, so exposure is on the order of the full Windows installed base.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Mark of the Web Security Feature Bypass Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016
Weakness
CWE-693
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

In the news