cbcvebase.
CVE-2024-21351
published 2024-02-13

CVE-2024-21351: Windows SmartScreen Security Feature Bypass Vulnerability

PriorityP182high7.6CVSS 3.1
AVNACLPRNUIRSUCLIHAL
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-03-05
Exploited in the wild
EPSS
30.34%
98.0th percentile
Windows SmartScreen Security Feature Bypass Vulnerability

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.2046910.0.10240.20469
microsoftwindows_10_1607< 10.0.14393.670910.0.14393.6709
microsoftwindows_10_1809< 10.0.17763.545810.0.17763.5458
microsoftwindows_10_21h2< 10.0.19044.404610.0.19044.4046
microsoftwindows_10_22h2< 10.0.19045.404610.0.19045.4046
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.2046910.0.10240.20469
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.670910.0.14393.6709
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.545810.0.17763.5458
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.545810.0.17763.5458
microsoftwindows_10_version_21h2>= 10.0.19043.0 < 10.0.19044.404610.0.19044.4046
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.404610.0.19045.4046
microsoftwindows_11_21h2< 10.0.22000.277710.0.22000.2777
microsoftwindows_11_22h2< 10.0.22621.315510.0.22621.3155
microsoftwindows_11_23h2< 10.0.22631.315510.0.22631.3155
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22000.277710.0.22000.2777
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.315510.0.22621.3155
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.315510.0.22631.3155
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.315510.0.22631.3155
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.670910.0.14393.6709
microsoftwindows_server_2019< 10.0.17763.545810.0.17763.5458
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.545810.0.17763.5458
microsoftwindows_server_2022< 10.0.20348.232210.0.20348.2322
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.232210.0.20348.2322
microsoftwindows_server_2022_23h2< 10.0.25398.70910.0.25398.709
msrcwindows_10

Detection & IOCsextracted from sources · hover to see the quote

domainfxbulls[.]ru
  • Monitor for internet shortcut (.URL) files that reference other shortcut files (shortcut-within-shortcut chaining), which was the technique used to evade SmartScreen MotW checks.
  • Detect abuse of WebDAV components in conjunction with internet shortcut (.URL) files, a key TTP of the Water Hydra campaign exploiting this CVE.
  • Alert on execution of MSI files delivered via spear-phishing that bypass SmartScreen, particularly in the context of forex/financial trading lures on forums and Telegram channels.
  • Check for NTFS Alternate Data Stream (ADS) ZoneId=3 absence on files downloaded from the internet that should carry MotW, indicating potential SmartScreen bypass.
  • Hunt for DarkMe malware delivery as the final payload in campaigns exploiting this SmartScreen bypass, targeting financial market traders.
  • ·Exploitation requires user interaction — the attacker must send a malicious file and convince the user to open it; no forced execution is possible.
  • ·CVE-2024-21351 is confirmed exploited in the wild as of February 2024 Patch Tuesday; CISA remediation deadline was 2024-03-05.
  • ·This vulnerability is related to and was used alongside CVE-2024-21412, which itself bypasses the previously patched CVE-2023-36025; detections should account for chained exploitation.

CVSS provenance

nvdv3.17.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L
vulncheck7.6HIGH
cisa7.6HIGH
vendor_msrc7.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.