cbcvebase.
CVE-2024-21412
published 2024-02-13

CVE-2024-21412: Internet Shortcut Files Security Feature Bypass Vulnerability

PriorityP192high8.1CVSS 3.1
AVNACLPRNUIRSUCHIHAN
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2024-03-05
Exploited in the wild
EPSS
95.44%
99.9th percentile
Internet Shortcut Files Security Feature Bypass Vulnerability

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1809< 10.0.17763.545810.0.17763.5458
microsoftwindows_10_21h2< 10.0.19044.404610.0.19044.4046
microsoftwindows_10_22h2< 10.0.19045.404610.0.19045.4046
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.545810.0.17763.5458
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.545810.0.17763.5458
microsoftwindows_10_version_21h2>= 10.0.19043.0 < 10.0.19044.404610.0.19044.4046
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.404610.0.19045.4046
microsoftwindows_11_21h2< 10.0.22000.277710.0.22000.2777
microsoftwindows_11_22h2< 10.0.22621.315510.0.22621.3155
microsoftwindows_11_23h2< 10.0.22631.315510.0.22631.3155
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22000.277710.0.22000.2777
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.315510.0.22621.3155
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.315510.0.22631.3155
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.315510.0.22631.3155
microsoftwindows_server_2019< 10.0.17763.545810.0.17763.5458
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.545810.0.17763.5458
microsoftwindows_server_2022< 10.0.20348.232210.0.20348.2322
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.232210.0.20348.2322
microsoftwindows_server_2022_23h2< 10.0.25398.70910.0.25398.709
msrcwindows_10_version_1809_for_32-bit_systems
msrcwindows_10_version_1809_for_arm64-based_systems
msrcwindows_10_version_1809_for_x64-based_systems
msrcwindows_10_version_21h2_for_32-bit_systems
msrcwindows_10_version_21h2_for_arm64-based_systems
msrcwindows_10_version_21h2_for_x64-based_systems

Detection & IOCsextracted from sources · hover to see the quote

hash237D1BCA6E056DF5BB16A1216A434634109478F882D3B1D58344C801D184F95D
hash22EE095FA9456F878CFAFF8F2A4871EC550C4E9EE538975C1BBC7086CDE15EDE
hash1EA0E878E276481A6FAEAF016EC89231957B02CB55C3DD68F035B82E072E784B
hashfae4f96beda54a1ed4914537b0542182d3a020dd9db9d9995df37d303b88e6df
filenamescript.au3
filenamefiles.cab
path%tmp%\MW-
processNVIDIA Share.exe
processexpand.exe
domainwebcamcn[.]xyz
pathC:\Program Files(x86)\Sophos
  • Hunt for MSI files spawning expand.exe to decompress a CAB named 'files.cab' into a %tmp%\MW-* directory, followed by execution of a signed binary (e.g., NVIDIA Share.exe) for DLL sideloading — a key DarkGate stage-3 indicator.
  • Flag phishing lures using Google DoubleClick/DDM open redirect URLs in PDFs that chain to .MSI files — a delivery pattern observed in the CVE-2024-21412 DarkGate campaign.
  • CVE-2024-21412 was used as a bypass for the previously patched CVE-2023-36025; correlate detections for both vulnerabilities as threat actors chain them — the .MSI stage also exploits CVE-2023-36025 via a ZIP in the path.
  • ·CVE-2024-21412 is itself a bypass of the previously patched CVE-2023-36025; defenders should ensure both patches are applied as threat actors actively chain these vulnerabilities.
  • ·The DarkGate AutoIt loader's Sophos directory check string is obfuscated/distorted in newer versions ('CProgramDataSophos'), so detection rules targeting the exact string 'C:\Program Files(x86)\Sophos' may miss updated samples.

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
vulncheck8.8HIGH
cisa8.1HIGH
vendor_msrc8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.