⚠ Actively exploited
Added to CISA KEV on 2023-07-11. Federal agencies required to patch by 2023-08-01. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable..

CVE-2023-32049Microsoft Windows 10 Version 1607 vulnerability

19 documents10 sources
Severity
8.8HIGHNVD
EPSS
9.1%
top 7.34%
CISA KEV
KEV
Added 2023-07-11
Due 2023-08-01
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJul 11
KEV addedJul 11
KEV dueAug 1
Latest updateFeb 13
CISA Required Action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

Description

Windows SmartScreen Security Feature Bypass Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages24 packages

NVDmicrosoft/windows_10_1607< 10.0.14393.6085
NVDmicrosoft/windows_10_1809< 10.0.17763.4645
NVDmicrosoft/windows_10_21h2< 10.0.19041.3208
NVDmicrosoft/windows_10_22h2< 10.0.19045.3208
NVDmicrosoft/windows_11_21h2< 10.0.22000.2176

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8q3q-pcch-j42x: Windows SmartScreen Security Feature Bypass Vulnerability2023-07-11
VulnCheck
Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability2023

📋Vendor Advisories

2
CISA
Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability2023-07-11
Microsoft
Windows SmartScreen Security Feature Bypass Vulnerability2023-07-11

🕵️Threat Intelligence

14
Tenable
Microsoft’s February 2024 Patch Tuesday Addresses 73 CVEs (CVE-2024-21351, CVE-2024-21412)2024-02-13
Krebs
Fat Patch Tuesday, February 2024 Edition2024-02-13
Krebs
Fat Patch Tuesday, February 2024 Edition2024-02-13
Tenable
Microsoft’s November 2023 Patch Tuesday Addresses 57 CVEs (CVE-2023-36025)2023-11-14
Qualys
Evaluate Your Windows Endpoints for Storm-0978 Activity With Qualys Endpoint Security2023-07-14
CVE-2023-32049 — Microsoft vulnerability | cvebase