cbcvebase.
CVE-2024-29988
published 2024-04-09

CVE-2024-29988: SmartScreen Prompt Security Feature Bypass Vulnerability

PriorityP187high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-05-21
Exploited in the wild
EPSS
45.15%
98.7th percentile
SmartScreen Prompt Security Feature Bypass Vulnerability

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1809< 10.0.17763.569610.0.17763.5696
microsoftwindows_10_21h2< 10.0.19044.429110.0.19044.4291
microsoftwindows_10_22h2< 10.0.19045.429110.0.19045.4291
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.569610.0.17763.5696
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.569610.0.17763.5696
microsoftwindows_10_version_21h2>= 10.0.19043.0 < 10.0.19044.429110.0.19044.4291
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.429110.0.19045.4291
microsoftwindows_11_21h2< 10.0.22000.289910.0.22000.2899
microsoftwindows_11_22h2< 10.0.22621.344710.0.22621.3447
microsoftwindows_11_23h2< 10.0.22631.344710.0.22631.3447
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22000.289910.0.22000.2899
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.344710.0.22621.3447
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.344710.0.22631.3447
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.344710.0.22631.3447
microsoftwindows_server_2019< 10.0.17763.569610.0.17763.5696
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.569610.0.17763.5696
microsoftwindows_server_2022< 10.0.20348.240210.0.20348.2402
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.240210.0.20348.2402
microsoftwindows_server_2022_23h2< 10.0.25398.83010.0.25398.830
msrcwindows_10_version_1809_for_32-bit_systems
msrcwindows_10_version_1809_for_arm64-based_systems
msrcwindows_10_version_1809_for_x64-based_systems
msrcwindows_10_version_21h2_for_32-bit_systems
msrcwindows_10_version_21h2_for_arm64-based_systems
msrcwindows_10_version_21h2_for_x64-based_systems

Detection & IOCsextracted from sources · hover to see the quote

otherCVE-2024-21412
otherCVE-2023-38831
filenameZone.Identifier
bytes
ZoneId=3
  • Threat actors deliver exploits inside zipped files to evade EDR/NDR detection before using the SmartScreen bypass to execute malware — inspect zip archives arriving via email or download for embedded .url or .lnk files.
  • Monitor for Internet Shortcut (.url) and Shortcut (.lnk) files originating from WebDAV UNC paths (\\<host>@<port>\<share>) that lack a Zone.Identifier ADS / ZoneId=3 marking — absence of MotW on such files is a strong indicator of exploitation.
  • Detect use of the Windows search protocol to open WebDAV shares through Windows Explorer — this is a known delivery mechanism used by threat actors to control what files the victim sees on the share.
  • Alert on WebDAV UNC path access patterns (\\<IP>@<port>\<share>) from Windows Explorer (explorer.exe) — threat actors host malicious payloads on WebDAV shares accessed this way to strip MotW protections.
  • CVE-2024-29988 is part of an exploit chain — look for DarkMe RAT and DarkGate malware payloads disguised as legitimate software installers (Apple iTunes, Notion, NVIDIA) delivered via spearphishing to forex/stock trading communities.
  • ·The April 2024 patch only partially addressed the underlying vulnerability chain — CVE-2024-29988 is the second part of the exploit chain rooted in CVE-2024-21412; both patches are required for full remediation.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.