CVE-2024-21351
published 2024-02-13CVE-2024-21351: Windows SmartScreen Security Feature Bypass Vulnerability
PriorityP182high7.6CVSS 3.1
AVNACLPRNUIRSUCLIHAL
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-03-05
Exploited in the wild
EPSS
30.34%
98.0th percentile
Windows SmartScreen Security Feature Bypass Vulnerability
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.20469 | 10.0.10240.20469 |
| microsoft | windows_10_1607 | < 10.0.14393.6709 | 10.0.14393.6709 |
| microsoft | windows_10_1809 | < 10.0.17763.5458 | 10.0.17763.5458 |
| microsoft | windows_10_21h2 | < 10.0.19044.4046 | 10.0.19044.4046 |
| microsoft | windows_10_22h2 | < 10.0.19045.4046 | 10.0.19045.4046 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.20469 | 10.0.10240.20469 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.6709 | 10.0.14393.6709 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.5458 | 10.0.17763.5458 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.5458 | 10.0.17763.5458 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.4046 | 10.0.19044.4046 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.4046 | 10.0.19045.4046 |
| microsoft | windows_11_21h2 | < 10.0.22000.2777 | 10.0.22000.2777 |
| microsoft | windows_11_22h2 | < 10.0.22621.3155 | 10.0.22621.3155 |
| microsoft | windows_11_23h2 | < 10.0.22631.3155 | 10.0.22631.3155 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.2777 | 10.0.22000.2777 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.3155 | 10.0.22621.3155 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.3155 | 10.0.22631.3155 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.3155 | 10.0.22631.3155 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.6709 | 10.0.14393.6709 |
| microsoft | windows_server_2019 | < 10.0.17763.5458 | 10.0.17763.5458 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.5458 | 10.0.17763.5458 |
| microsoft | windows_server_2022 | < 10.0.20348.2322 | 10.0.20348.2322 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.2322 | 10.0.20348.2322 |
| microsoft | windows_server_2022_23h2 | < 10.0.25398.709 | 10.0.25398.709 |
| msrc | windows_10 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for internet shortcut (.URL) files that reference other shortcut files (shortcut-within-shortcut chaining), which was the technique used to evade SmartScreen MotW checks. ↗
- →Detect abuse of WebDAV components in conjunction with internet shortcut (.URL) files, a key TTP of the Water Hydra campaign exploiting this CVE. ↗
- →Alert on execution of MSI files delivered via spear-phishing that bypass SmartScreen, particularly in the context of forex/financial trading lures on forums and Telegram channels. ↗
- →Check for NTFS Alternate Data Stream (ADS) ZoneId=3 absence on files downloaded from the internet that should carry MotW, indicating potential SmartScreen bypass. ↗
- →Hunt for DarkMe malware delivery as the final payload in campaigns exploiting this SmartScreen bypass, targeting financial market traders. ↗
- ·Exploitation requires user interaction — the attacker must send a malicious file and convince the user to open it; no forced execution is possible. ↗
- ·CVE-2024-21351 is confirmed exploited in the wild as of February 2024 Patch Tuesday; CISA remediation deadline was 2024-03-05. ↗
- ·This vulnerability is related to and was used alongside CVE-2024-21412, which itself bypasses the previously patched CVE-2023-36025; detections should account for chained exploitation. ↗
CVSS provenance
nvdv3.17.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L
vulncheck7.6HIGH
cisa7.6HIGH
vendor_msrc7.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
cisa·2024-02-13·CVSS 7.6
CVE-2024-21351 [HIGH] CWE-94 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Vulnerability: Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Affected: Microsoft Windows
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience and inject code to potentially gain code execution, which could lead to some data exposure, lack of system availability, or both.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21351; https://nvd.nist.gov/vuln/detail/CVE-2024-21351
Remediation Due Date: 2024-03-05
Microsoft
Windows SmartScreen Security Feature Bypass Vulnerability
vendor_msrc·2024-02-13·CVSS 7.6
CVE-2024-21351 [HIGH] CWE-94 Windows SmartScreen Security Feature Bypass Vulnerability
Windows SmartScreen Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could bypass the SmartScreen user experience.
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L), a total loss of integrity (I:H), and some loss of availability (A:L). What does that mean for this vulnerability?
The vulnerability allows a malicious actor to inject code into SmartScreen and potentially gain code execution, which could potentially lead to some data exposure, lack of system availability, or both.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction
GHSA
GHSA-w4vx-2pcg-383r: Windows SmartScreen Security Feature Bypass Vulnerability
ghsa_unreviewed·2024-02-13
CVE-2024-21351 [HIGH] CWE-94 GHSA-w4vx-2pcg-383r: Windows SmartScreen Security Feature Bypass Vulnerability
Windows SmartScreen Security Feature Bypass Vulnerability
VulnCheck
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
vulncheck·2024·CVSS 7.6
CVE-2024-21351 [HIGH] CWE-94 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience and inject code to potentially gain code execution, which could lead to some data exposure, lack of system availability, or both.
Affected: Microsoft Windows
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2024-Feb; https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21351; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://ti.qianxin.com/uploads/2024/08/19/2274f632f6a1d8acd2f180
No detection rules found.
No public exploits indexed.
Checkpoint
19th February – Threat Intelligence Report
blogs_checkpoint·2024-02-19
CVE-2024-21413 19th February – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 19th February – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 19th February, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Romanian hospital patients’ data management system, Hipocrate IT Platform, was hit by a ransomware attack, leading to data encryption of over 20 Bucharest hospitals. The attack rendered the hospital staff resorting to manual logging and tracking of critical patient data and progress. Another 79 Romanian hospitals using
Tenable
Microsoft’s February 2024 Patch Tuesday Addresses 73 CVEs (CVE-2024-21351, CVE-2024-21412)
blogs_tenable·2024-02-13·CVSS 7.6
[HIGH] Microsoft’s February 2024 Patch Tuesday Addresses 73 CVEs (CVE-2024-21351, CVE-2024-21412)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Microsoft February 2024 Patch Tuesday fixes 2 zero-days, 73 flaws
blogs_bleepingcomputer·2024-02-13·CVSS 7.6
[HIGH] Microsoft February 2024 Patch Tuesday fixes 2 zero-days, 73 flaws
## Microsoft February 2024 Patch Tuesday fixes 2 zero-days, 73 flaws
## Lawrence Abrams
16 Elevation of Privilege Vulnerabilities
3 Security Feature Bypass Vulnerabilities
30 Remote Code Execution Vulnerabilities
5 Information Disclosure Vulnerabilities
9 Denial of Service Vulnerabilities
10 Spoofing Vulnerabilities
The total count of 73 flaws does not include 6 Microsoft Edge flaws fixed on February 8th and 1 Mariner flaw.
To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5034765 cumulative update and the Windows 10 KB5034763 update .
## Two zero-days fixed
This month's Patch Tuesday fixes two actively exploited zero-day vulnerabilities, which Microsoft classifies as a flaw that is publicly disclosed or ac
Qualys
Microsoft and Adobe Patch Tuesday, February 2024 Security Update Review | Qualys
blogs_qualys·2024-02-13
Microsoft and Adobe Patch Tuesday, February 2024 Security Update Review | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for February 2024
- Adobe Patches for February 2024
- Zero-day Vulnerabilities Patched in February Patch Tuesday Edition
- Other Critical Severity Vulnerabilities Patched in February Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- Qualys Monthly Webinar Series
The new Microsoft Patch Tuesday Edition for February 2024 is now live! We invite you to join us to review and discuss the details of these security updates and patches.
## Microsoft Patch Tuesday for February 2024
Microsoft Patch
Bleepingcomputer
Hackers used new Windows Defender zero-day to drop DarkMe malware
blogs_bleepingcomputer·2024-02-13·CVSS 8.8
CVE-2024-21412 [HIGH] Hackers used new Windows Defender zero-day to drop DarkMe malware
## Hackers used new Windows Defender zero-day to drop DarkMe malware
## Sergiu Gatlan
"However, the attacker would have no way to force a user to view the attacker-controlled content. Instead, the attacker would have to convince them to take action by clicking on the file link."
Trend Micro security researcher Peter Girnus, credited for reporting this zero-day, revealed that the CVE-2024-21412 flaw bypasses another Defender SmartScreen vulnerability (CVE-2023-36025).
CVE-2023-36025 was patched during the November 2023 Patch Tuesday , and, as Trend Micro revealed last month, it was also exploited to bypass Windows security prompts when opening URL files to deploy the Phemedrone info-stealer malware .
## Zero-day used to target financial market traders
The zero-day that Microsoft patch
Qualys
Microsoft and Adobe Patch Tuesday, February 2024 Security Update Review
blogs_qualys·2024-02-13
Microsoft and Adobe Patch Tuesday, February 2024 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for February 2024
Adobe Patches for February 2024
Zero-day Vulnerabilities Patched in February Patch Tuesday Edition
Other Critical Severity Vulnerabilities Patched in February Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Qualys Monthly Webinar Series
The new Microsoft Patch Tuesday Edition for February 2024 is now live! We invite you to join us to review and discuss the details of these security updates and patches.
## Microsoft Patch Tuesday for February 2024
Microsoft Patch Tuesday’s Fe
Talos
First Microsoft Patch Tuesday zero-day of 2024 disclosed as part of group of 75 vulnerabilities
blogs_talos·2024-02-13·CVSS 6.5
[MEDIUM] First Microsoft Patch Tuesday zero-day of 2024 disclosed as part of group of 75 vulnerabilities
Microsoft followed up one of the lightest recent Patch Tuesdays in January with a large release of vulnerabilities on Tuesday, although still far from numbers seen in the past.
In all, February’s security update from Microsoft includes 75 vulnerabilities, three of which are considered critical. There are 69 “important” vulnerabilities, according to Microsoft, and three that are of “moderate” severity.
Although considered of moderate risk, one of the vulnerabilities is being actively exploited in the wild — CVE-2024-21351, a security feature bypass vulnerability in Windows SmartScreen. “Smart screen” protects users from malicious websites and files downloaded from the internet. Exploiting this vulnerability may allow a user to be tricked into downloading and executing a file from the inte
Krebs
Fat Patch Tuesday, February 2024 Edition
blogs_krebs·2024-02-13·CVSS 5.4
CVE-2024-21412 [MEDIUM] Fat Patch Tuesday, February 2024 Edition
Microsoft Corp. today pushed software updates to plug more than 70 security holes in its Windows operating systems and related products, including two zero-day vulnerabilities that are already being exploited in active attacks.
Top of the heap on this Fat Patch Tuesday is CVE-2024-21412, a “security feature bypass” in the way Windows handles Internet Shortcut Files that Microsoft says is being targeted in active exploits. Redmond’s advisory for this bug says an attacker would need to convince or trick a user into opening a malicious shortcut file.
Researchers at Trend Micro have tied the ongoing exploitation of CVE-2024-21412 to an advanced persistent threat group dubbed “Water Hydra,” which they say has being using the vulnerability to execute a malicious Microsoft Installer File (.msi)
Krebs
Fat Patch Tuesday, February 2024 Edition
blogs_krebs·2024-02-13·CVSS 5.4
CVE-2024-21412 [MEDIUM] Fat Patch Tuesday, February 2024 Edition
Microsoft Corp. today pushed software updates to plug more than 70 security holes in its Windows operating systems and related products, including two zero-day vulnerabilities that are already being exploited in active attacks.
Top of the heap on this Fat Patch Tuesday is CVE-2024-21412 , a “security feature bypass” in the way Windows handles Internet Shortcut Files that Microsoft says is being targeted in active exploits. Redmond’s advisory for this bug says an attacker would need to convince or trick a user into opening a malicious shortcut file.
Researchers at Trend Micro have tied the ongoing exploitation of CVE-2024-21412 to an advanced persistent threat group dubbed “ Water Hydra ,” which they say has being using the vulnerability to execute a malicious Microsoft Installer File (.m
Talos
First Microsoft Patch Tuesday zero-day of 2024 disclosed as part of group of 75 vulnerabilities
blogs_talos·2024-02-13·CVSS 6.5
[MEDIUM] First Microsoft Patch Tuesday zero-day of 2024 disclosed as part of group of 75 vulnerabilities
## First Microsoft Patch Tuesday zero-day of 2024 disclosed as part of group of 75 vulnerabilities
Microsoft followed up one of the lightest recent Patch Tuesdays in January with a large release of vulnerabilities on Tuesday, although still far from numbers seen in the past.
In all, February’s security update from Microsoft includes 75 vulnerabilities, three of which are considered critical. There are 69 “important” vulnerabilities, according to Microsoft, and three that are of “moderate” severity.
Although considered of moderate risk, one of the vulnerabilities is being actively exploited in the wild — CVE-2024-21351 , a security feature bypass vulnerability in Windows SmartScreen. “Smart screen” protects users from malicious websites and files downloaded from the internet. Exploiting
Trendmicro
The February 2024 Security Update Review
blogs_trendmicro·2024-02-12·CVSS 7.5
[HIGH] The February 2024 Security Update Review
## The February 2024 Security Update Review
Get the Feburary 2024 security update and review.
By: Dustin Childs 2024/02/12 Read time: ( words)
Save to Folio
It’s the second patch Tuesday of the year, and Adobe and Microsoft have released a fresh crop of security updates just in time to be our Valentine. Take a break from your other activities and join us as we review the details of their latest advisories. For those interested in the Microsoft 0-day discovered by the ZDI Threat Hunting Team, you can watch this special edition of the Patch Report:
If you’d rather watch the full video recap covering the entire release, you can check out here:
CVE
Title
Severity
CVSS
Public
Exploited
Type
CVE-2024-21412
Internet Shortcut Files Security Feature Bypass Vulnerability
Important
8.
Trendmicro
The February 2024 Security Update Review
blogs_trendmicro·2024-02-12
The February 2024 Security Update Review
# The February 2024 Security Update Review
Get the Feburary 2024 security update and review.
By: Dustin Childs
2024/02/12
Read time: ( words)
Save to Folio
It’s the second patch Tuesday of the year, and Adobe and Microsoft have released a fresh crop of security updates just in time to be our Valentine. Take a break from your other activities and join us as we review the details of their latest advisories. For those interested in the Microsoft 0-day discovered by the ZDI Threat Hunting Team, you can watch this special edition of the Patch Report:
If you’d rather watch the full video recap covering the entire release, you can check out here:
Adobe Patches for February 2024
For February, Adobe released six patches addressing 29 CVEs in Adobe Acrobat and Reader, Commerce, Substance 3D
Trendmicro
The February 2024 Security Update Review
blogs_trendmicro·2024-02-12·CVSS 7.5
[HIGH] The February 2024 Security Update Review
## The February 2024 Security Update Review
Get the Feburary 2024 security update and review.
By: Dustin Childs Feb 12, 2024 Read time: ( words)
Save to Folio
It’s the second patch Tuesday of the year, and Adobe and Microsoft have released a fresh crop of security updates just in time to be our Valentine. Take a break from your other activities and join us as we review the details of their latest advisories. For those interested in the Microsoft 0-day discovered by the ZDI Threat Hunting Team, you can watch this special edition of the Patch Report:
If you’d rather watch the full video recap covering the entire release, you can check out here:
CVE
Title
Severity
CVSS
Public
Exploited
Type
CVE-2024-21412
Internet Shortcut Files Security Feature Bypass Vulnerability
Important
Trendmicro
The February 2024 Security Update Review
blogs_trendmicro·2024-02-12·CVSS 7.5
[HIGH] The February 2024 Security Update Review
## The February 2024 Security Update Review
Get the February 2024 security update and review.
By: Dustin Childs Feb 12, 2024 Read time: ( words)
Save to Folio
It’s the second patch Tuesday of the year, and Adobe and Microsoft have released a fresh crop of security updates just in time to be our Valentine. Take a break from your other activities and join us as we review the details of their latest advisories. For those interested in the Microsoft 0-day discovered by the ZDI Threat Hunting Team, you can watch this special edition of the Patch Report:
If you’d rather watch the full video recap covering the entire release, you can check out here:
CVE
Title
Severity
CVSS
Public
Exploited
Type
CVE-2024-21412
Internet Shortcut Files Security Feature Bypass Vulnerability
Important
Crowdstrike
February 2024 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] February 2024 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2024-02-13
Published
2024-02-13
Added to CISA KEV
Exploited in the wild