CVE-2024-38217
KEV PoC massMark of the Web (MOTW) Security Feature Bypass in Microsoft Windows - Actively Exploited
CISA: Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability
CVE-2024-38217 is a protection mechanism failure (CWE-693) in Microsoft Windows' Mark of the Web (MOTW) feature, which tags files downloaded from the internet so Windows can apply security warnings. An attacker can craft a file whose MOTW marking fails or is not correctly applied; when a user is tricked into opening or saving that file (user interaction is required per the CVSS vector), Windows' MOTW-based protections, such as SmartScreen/Smart App Control prompts, are bypassed. The scored impact is limited to integrity and availability (CVSS 3.1: 5.4, medium), but the bypass can make malicious files appear trustworthy to users. All of the listed Windows 10, Windows 11, and Windows Server releases are affected. The flaw was actively exploited in the wild at the time of September 2024 Patch Tuesday, was added to CISA's KEV on 2024-09-10, and a public proof-of-concept demonstrating a bypass of Smart App Control has been published by Elastic Security Labs; EPSS estimates a 10% probability of exploitation in the next 30 days (95th percentile).
What to do: Apply Microsoft's September 2024 (or later) Windows cumulative security updates across all listed Windows 10, Windows 11, and Windows Server releases, and verify the fix actually took effect, since reporting indicates a Microsoft code defect left some systems without an effective earlier fix. Until patched, exercise caution opening or saving files obtained from the internet, as exploitation requires user interaction. Organizations subject to CISA KEV requirements must apply the vendor mitigations or discontinue use of affected products per the KEV directive.
| Microsoft Windows 10 | 1507, 1607, 1809, 21H2, 22H2 |
| Microsoft Windows 11 | 21H2, 22H2, 23H2, 24H2 |
| Microsoft Windows Server | 2008, 2012, 2016 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows Mark of the Web Security Feature Bypass Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016
- Weakness
- CWE-693
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L