Security Affairs newsletter Round 485 by Pierluigi Paganini
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-38213 | Mark of the Web Security Feature Bypass in Microsoft Windows (CVE-2024-38213) CVE-2024-38213 is a security feature bypass in the Windows Mark of the Web (MotW) mechanism that underpins SmartScreen warnings, allowing a maliciously crafted file to bypass the usual 'file downloaded from the internet' prompt. It is triggered when a user opens attacker-supplied content that defeats or strips the MotW flag, meaning the exploit requires user interaction (CVSS UI:R) and a network-accessible delivery vector such as email or a web download. On its own the flaw grants no confidentiality or availability impact but high integrity impact (CVSS 3.1 score 6.5), and in practice it is used to evade SmartScreen protections, typically chained with other bugs to achieve fuller compromise. It affects an extremely broad population: Windows 10 (1507 through 22H2), Windows 11 (21H2 through 23H2), and Windows Server 2012 through 2022. The flaw was one of six zero-days under active attack in Microsoft's August 2024 Patch Tuesday release and was added to CISA's Known Exploited Vulnerabilities catalog on 2024-08-13; EPSS puts its 30-day exploitation probability at 13.6% (96th percentile). Do: Apply the August 2024 Microsoft security updates (Patch Tuesday, released 2024-08-13) for every affected Windows 10, Windows 11, and Windows Server version, per CISA's KEV required action; treat this as a priority patch given confirmed in-the-wild exploitation. Because the bypass requires a user to open attacker-supplied content, reinforce caution around emailed and downloaded files until patching is complete, and confirm from vendor guidance whether any interim mitigations apply in environments that cannot patch immediately. | 6.5 | 14% | KEV |
| masshundreds of millions to billions of Windows desktop and server installations |
Full article525 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
Cybercrime
Hackers leak 2.7 billion data records with Social Security numbers
Disrupting Russian Cybercrime: WWH-Club Admins Arrested
International Investigation Leads to Shutdown of Ransomware Group
Six ransomware gangs behind over 50% of 2024 attacks
Unconfirmed Hack of 2.9 Billion Records at National Public Data Sparks Media Frenzy Amid Lawsuits
Suspected head of prolific cybercrime groups arrested and extradited
Texas firm says it lost $60M in a bank wire transfer scam
Ransomware attack on Flint affecting city services as FBI investigates incident
Inside the “3 Billion People” National Public Data Breach
NationalPublicData.com Hack Exposes a Nation’s Data
Leaked Environment Variables Allow Large-Scale Extortion Operation of Cloud Environments
Malware
Deciphering the Brain Cipher Ransomware
Ideal typosquat ‘solana-py’ steals your crypto wallet keys
Ransomware attackers introduce new EDR killer to their arsenal
A Deep Dive into a New ValleyRAT Campaign Targeting Chinese Speakers
Tusk: unraveling a complex infostealer campaign
Hacking
Chained for attack: OpenVPN vulnerabilities discovered leading to RCE and LPE
Musk’s interview with Trump marred by technical glitches
Massive cyberattack rocks Central Bank of Iran, computer system paralyzed – report
Ongoing Social Engineering Campaign Refreshes Payloads
Threat Actor Tools Found that Bypass Antivirus, Delete Backups, Disable Systems
Want to Win a Bike Race? Hack Your Rival’s Wireless Shifters
Zero-Click Exploit Concerns Drive Urgent Patching of Windows TCP/IP Flaw
iVerify Discovers Android Vulnerability Impacting Millions of Pixel Devices Around the World
CVE-2024-38213: Copy2Pwn Exploit Evades Windows Web Protections
Unicoin hints at potential data meddling after G-Suite compromise
Intelligence and Information Warfare
We received internal Trump documents from ‘Robert.’ Then the campaign confirmed it was hacked
EastWind Campaign: New CloudSorcerer Attacks on Russian Government Organizations
UAC-0198: Widespread Distribution of ANONVNC (MESHAGENT) Among Ukrainian Government Organizations
A Dive into Earth Baku’s Latest Campaign
Pentagon to Conduct Massive Experiment for Connect-Everything Initiative
Iranian backed group steps up phishing campaigns against Israel, U.S.
NATO must recognize the potential of open-source intelligence
Disrupting a covert Iranian influence operation
Cybersecurity
OpenSSH pre-authentication async signal safety issue
THE AUGUST 2024 SECURITY UPDATE REVIEW
NIST finalizes trio of post-quantum encryption standards
German Cyber Agency Wants Changes in Microsoft, CrowdStrike Products After Tech Outage
Inside the FBI’s Dashboard for Wiretapping the World
Quantum Computers Will Kill Digital Security. These Algorithms Could Stop Them
An A.I.-powered version of Mr. Musk has appeared in thousands of inauthentic ads, contributing to billions in fraud
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
you might also like
leave a comment
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/167207/breaking-news/security-affairs-newsletter-round-485-by-pierluigi-paganini-international-edition.html