CVE-2024-21412
published 2024-02-13CVE-2024-21412: Internet Shortcut Files Security Feature Bypass Vulnerability
high8.1CVSS 3.1
AVNACLPRNUIRSUCHIHAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-03-05
Exploited in the wild
Internet Shortcut Files Security Feature Bypass Vulnerability
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1809 | < 10.0.17763.5458 | 10.0.17763.5458 |
| microsoft | windows_10_21h2 | < 10.0.19044.4046 | 10.0.19044.4046 |
| microsoft | windows_10_22h2 | < 10.0.19045.4046 | 10.0.19045.4046 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.5458 | 10.0.17763.5458 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.5458 | 10.0.17763.5458 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.4046 | 10.0.19044.4046 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.4046 | 10.0.19045.4046 |
| microsoft | windows_11_21h2 | < 10.0.22000.2777 | 10.0.22000.2777 |
| microsoft | windows_11_22h2 | < 10.0.22621.3155 | 10.0.22621.3155 |
| microsoft | windows_11_23h2 | < 10.0.22631.3155 | 10.0.22631.3155 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.2777 | 10.0.22000.2777 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.3155 | 10.0.22621.3155 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.3155 | 10.0.22631.3155 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.3155 | 10.0.22631.3155 |
| microsoft | windows_server_2019 | < 10.0.17763.5458 | 10.0.17763.5458 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.5458 | 10.0.17763.5458 |
| microsoft | windows_server_2022 | < 10.0.20348.2322 | 10.0.20348.2322 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.2322 | 10.0.20348.2322 |
| microsoft | windows_server_2022_23h2 | < 10.0.25398.709 | 10.0.25398.709 |
| msrc | windows_10_version_1809_for_32-bit_systems | — | — |
| msrc | windows_10_version_1809_for_arm64-based_systems | — | — |
| msrc | windows_10_version_1809_for_x64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_21h2_for_arm64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_x64-based_systems | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
vulncheck8.8HIGH
cisa8.1HIGH