CVE-2024-29988
published 2024-04-09CVE-2024-29988: SmartScreen Prompt Security Feature Bypass Vulnerability
PriorityP187high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-05-21
Exploited in the wild
EPSS
45.15%
98.7th percentile
SmartScreen Prompt Security Feature Bypass Vulnerability
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1809 | < 10.0.17763.5696 | 10.0.17763.5696 |
| microsoft | windows_10_21h2 | < 10.0.19044.4291 | 10.0.19044.4291 |
| microsoft | windows_10_22h2 | < 10.0.19045.4291 | 10.0.19045.4291 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.5696 | 10.0.17763.5696 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.5696 | 10.0.17763.5696 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.4291 | 10.0.19044.4291 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.4291 | 10.0.19045.4291 |
| microsoft | windows_11_21h2 | < 10.0.22000.2899 | 10.0.22000.2899 |
| microsoft | windows_11_22h2 | < 10.0.22621.3447 | 10.0.22621.3447 |
| microsoft | windows_11_23h2 | < 10.0.22631.3447 | 10.0.22631.3447 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.2899 | 10.0.22000.2899 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.3447 | 10.0.22621.3447 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.3447 | 10.0.22631.3447 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.3447 | 10.0.22631.3447 |
| microsoft | windows_server_2019 | < 10.0.17763.5696 | 10.0.17763.5696 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.5696 | 10.0.17763.5696 |
| microsoft | windows_server_2022 | < 10.0.20348.2402 | 10.0.20348.2402 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.2402 | 10.0.20348.2402 |
| microsoft | windows_server_2022_23h2 | < 10.0.25398.830 | 10.0.25398.830 |
| msrc | windows_10_version_1809_for_32-bit_systems | — | — |
| msrc | windows_10_version_1809_for_arm64-based_systems | — | — |
| msrc | windows_10_version_1809_for_x64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_21h2_for_arm64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_x64-based_systems | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
ZoneId=3
- →Threat actors deliver exploits inside zipped files to evade EDR/NDR detection before using the SmartScreen bypass to execute malware — inspect zip archives arriving via email or download for embedded .url or .lnk files. ↗
- →Monitor for Internet Shortcut (.url) and Shortcut (.lnk) files originating from WebDAV UNC paths (\\<host>@<port>\<share>) that lack a Zone.Identifier ADS / ZoneId=3 marking — absence of MotW on such files is a strong indicator of exploitation. ↗
- →Detect use of the Windows search protocol to open WebDAV shares through Windows Explorer — this is a known delivery mechanism used by threat actors to control what files the victim sees on the share. ↗
- →Alert on WebDAV UNC path access patterns (\\<IP>@<port>\<share>) from Windows Explorer (explorer.exe) — threat actors host malicious payloads on WebDAV shares accessed this way to strip MotW protections. ↗
- →CVE-2024-29988 is part of an exploit chain — look for DarkMe RAT and DarkGate malware payloads disguised as legitimate software installers (Apple iTunes, Notion, NVIDIA) delivered via spearphishing to forex/stock trading communities. ↗
- ·The April 2024 patch only partially addressed the underlying vulnerability chain — CVE-2024-29988 is the second part of the exploit chain rooted in CVE-2024-21412; both patches are required for full remediation. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qpqh-hxc9-r48w: SmartScreen Prompt Security Feature Bypass Vulnerability
ghsa_unreviewed·2024-04-09
CVE-2024-29988 [HIGH] CWE-693 GHSA-qpqh-hxc9-r48w: SmartScreen Prompt Security Feature Bypass Vulnerability
SmartScreen Prompt Security Feature Bypass Vulnerability
VulnCheck
Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability
vulncheck·2024·CVSS 7.8
CVE-2024-29988 [HIGH] CWE-693 Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability
Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability
Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-38831 and CVE-2024-21412 to execute a malicious file.
Affected: Microsoft SmartScreen Prompt
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://www.zerodayinitiative.com/blog/2024/4/9/the-april-2024-security-updates-review; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.zerodayinitiative.com/blog/2024/8/14/cve-2024-38213-copy2pwn-exploit-evades-windows-web-protections; http
CISA
Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability
cisa·2024-04-30·CVSS 7.8
CVE-2024-29988 [HIGH] CWE-693 Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability
Vulnerability: Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability
Affected: Microsoft SmartScreen Prompt
Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-38831 and CVE-2024-21412 to execute a malicious file.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29988; https://nvd.nist.gov/vuln/detail/CVE-2024-29988
Remediation Due Date: 2024-05-21
Microsoft
SmartScreen Prompt Security Feature Bypass Vulnerability
vendor_msrc·2024-04-09·CVSS 8.8
CVE-2024-29988 [HIGH] CWE-693 SmartScreen Prompt Security Feature Bypass Vulnerability
SmartScreen Prompt Security Feature Bypass Vulnerability
FAQ: How could an attacker exploit the vulnerability?
In an email or instant message attack scenario, the attacker could send the targeted user a specially crafted file that is designed to exploit the remote code execution vulnerability.
In any case an attacker would have no way to force a user to view attacker-controlled content. Instead, an attacker would have to convince a user to take action. For example, an attacker could entice a user to either click a link that directs the user to the attacker's site or send a malicious attachment.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
A user needs to be tricked into running malicious files.
FAQ: How could an atta
No detection rules found.
No public exploits indexed.
Trendmicro
CVE-2024-38213: Copy2Pwn Exploit Evades Windows Web Protections
blogs_trendmicro·2024-08-15·CVSS 8.1
CVE-2024-38213 [HIGH] CVE-2024-38213: Copy2Pwn Exploit Evades Windows Web Protections
# CVE-2024-38213: Copy2Pwn Exploit Evades Windows Web Protections
Learn how the cve-2024-38213 and copy2pwn exploit evades Windows web protections.
By: Peter Girnus
2024/08/15
Read time: ( words)
Save to Folio
Zero Day Initiative threat researchers discovered CVE-2024-38213, a simple and effective way to bypass Windows mark-of-the-web protections leading to remote code execution.
In March 2024, Trend Micro’s Zero Day Initiative Threat Hunting team started analyzing samples connected to the activity carried out by DarkGate operators to infect users through copy-and-paste operations. This DarkGate campaign was an update from a previous campaign in which the DarkGate operators were exploiting a zero-day vulnerability, CVE-2024-21412, which we disclosed to Microsoft earlier this year.
T
Bleepingcomputer
New Windows SmartScreen bypass exploited as zero-day since March
blogs_bleepingcomputer·2024-08-13·CVSS 8.1
[HIGH] New Windows SmartScreen bypass exploited as zero-day since March
## New Windows SmartScreen bypass exploited as zero-day since March
## Sergiu Gatlan
"An attacker who successfully exploited this vulnerability could bypass the SmartScreen user experience. An attacker must send the user a malicious file and convince them to open it," Redmond explains in a security advisory published on Tuesday.
Despite the increased difficulty in exploiting it, Trend Micro security researcher Peter Girnus discovered that the vulnerability was being exploited in the wild in March. Girnus reported the attacks to Microsoft, who patched the flaw during the June 2024 Patch Tuesday. However, the company forgot to include the advisory with that month's security updates (or with July's).
"In March 2024, Trend Micro's Zero Day Initiative Threat Hunting team started analyzing s
Checkpoint
15th April – Threat Intelligence Report
blogs_checkpoint·2024-04-15
CVE-2024-29990 15th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 15th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 15th April, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Japanese optics giant Hoya Corporation has been a victim of a ransomware attack that impacted its major IT infrastructure and various business divisions. Hunters International ransomware gang claimed responsibility for the attack and demanded a ransom of $10M for alleged 1.7M stolen files.
Check Point Harmony Endpoint and Th
Qualys
Microsoft and Adobe Patch Tuesday, April 2024 Security Update Review
blogs_qualys·2024-04-09
Microsoft and Adobe Patch Tuesday, April 2024 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for April 2024
Adobe Patches for April 2024
Other Critical Severity Vulnerabilities Patched in April Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Qualys Monthly Webinar Series
Welcome to another insightful dive into Microsoft’s Patch Tuesday! This month’s security updates address a vast number of vulnerabilities in multiple popular products, features, and roles. We invite you to join us to review and discuss the details of these security updates and patches.
## Microsoft Patch Tuesday for Ap
Trendmicro
The April 2024 Security Updates Review
blogs_trendmicro·2024-04-09
The April 2024 Security Updates Review
# The April 2024 Security Updates Review
Get the April 2024 security update and review.
By: Dustin Childs
2024/04/09
Read time: ( words)
Save to Folio
It’s the second Tuesday of the month, and Adobe and Microsoft have released a fresh crop of security updates. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for April 2024
For April, Adobe released nine patches addressing 24 CVEs in Adobe After Effects, Photoshop, Commerce, InDesign, Experience Manager, Media Encoder, Bridge, Illustrator, and Adobe Animate. The largest of these updates is for Experience Manager, however, all of the bugs being patched are simple Cross
Bleepingcomputer
Microsoft fixes two Windows zero-days exploited in malware attacks
blogs_bleepingcomputer·2024-04-09·CVSS 6.7
CVE-2024-26234 [MEDIUM] Microsoft fixes two Windows zero-days exploited in malware attacks
## Microsoft fixes two Windows zero-days exploited in malware attacks
## Sergiu Gatlan
Microsoft has fixed two actively exploited zero-day vulnerabilities during the April 2024 Patch Tuesday, although the company failed to initially tag them as such.
The first, tracked as CVE-2024-26234 and described as a proxy driver spoofing vulnerability, was issued to track a malicious driver signed using a valid Microsoft Hardware Publisher Certificate that was found by Sophos X-Ops in December 2023 and reported by team lead Christopher Budd.
This malicious file was labeled as "Catalog Authentication Client Service" by "Catalog Thales," likely an attempt to impersonate Thales Group. However, further investigation revealed that it was previously bundled with a marketing software called LaiXi Androi
Tenable
Microsoft’s April 2024 Patch Tuesday Addresses 147 CVEs (CVE-2024-29988)
blogs_tenable·2024-04-09·CVSS 8.8
[HIGH] Microsoft’s April 2024 Patch Tuesday Addresses 147 CVEs (CVE-2024-29988)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Microsoft April 2024 Patch Tuesday fixes 150 security flaws, 67 RCEs
blogs_bleepingcomputer·2024-04-09·CVSS 8.1
[HIGH] Microsoft April 2024 Patch Tuesday fixes 150 security flaws, 67 RCEs
## Microsoft April 2024 Patch Tuesday fixes 150 security flaws, 67 RCEs
## Lawrence Abrams
There were also fixes for twenty-six Secure Boot bypasses released this month, including two from Lenovo.
The number of bugs in each vulnerability category is listed below:
31 Elevation of Privilege Vulnerabilities
29 Security Feature Bypass Vulnerabilities
67 Remote Code Execution Vulnerabilities
13 Information Disclosure Vulnerabilities
7 Denial of Service Vulnerabilities
3 Spoofing Vulnerabilities
The total count of 150 flaws does not include 5 Microsoft Edge flaws fixed on April 4th and 2 Mariner flaws. Mariner is an open-source Linux distribution developed by Microsoft for its Microsoft Azure services.
To learn more about the non-security updates released today, you can review our ded
Trendmicro
The April 2024 Security Updates Review
blogs_trendmicro·2024-04-09
The April 2024 Security Updates Review
## The April 2024 Security Updates Review
Get the April 2024 security update and review.
By: Dustin Childs 2024/04/09 Read time: ( words)
Save to Folio
It’s the second Tuesday of the month, and Adobe and Microsoft have released a fresh crop of security updates. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for April 2024
For April, Adobe released nine patches addressing 24 CVEs in Adobe After Effects, Photoshop, Commerce, InDesign, Experience Manager, Media Encoder, Bridge, Illustrator, and Adobe Animate. The largest of these updates is for Experience Manager , however, all of the bugs being patched are simple Cros
Krebs
April’s Patch Tuesday Brings Record Number of Fixes
blogs_krebs·2024-04-09·CVSS 8.1
[HIGH] April’s Patch Tuesday Brings Record Number of Fixes
If only Patch Tuesdays came around infrequently — like total solar eclipse rare — instead of just creeping up on us each month like The Man in the Moon. Although to be fair, it would be tough for Microsoft to eclipse the number of vulnerabilities fixed in this month’s patch batch — a record 147 flaws in Windows and related software.
Yes, you read that right. Microsoft today released updates to address 147 security holes in Windows, Office , Azure , .NET Framework , Visual Studio , SQL Server , DNS Server , Windows Defender , Bitlocker , and Windows Secure Boot .
“This is the largest release from Microsoft this year and the largest since at least 2017,” said Dustin Childs , from Trend Micro’s Zero Day Initiative (ZDI). “As far as I can tell, it’s the largest Patch Tuesday release from Mic
Qualys
Security Update Review: Microsoft & Adobe April 2024 Patch Tuesday | Qualys
blogs_qualys·2024-04-09
Security Update Review: Microsoft & Adobe April 2024 Patch Tuesday | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for April 2024
- Adobe Patches for April 2024
- Other Critical Severity Vulnerabilities Patched in April Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- Qualys Monthly Webinar Series
Welcome to another insightful dive into Microsoft’s Patch Tuesday! This month’s security updates address a vast number of vulnerabilities in multiple popular products, features, and roles. We invite you to join us to review and discuss the details of these security updates and patches.
## Microsoft Patch Tu
Krebs
April’s Patch Tuesday Brings Record Number of Fixes
blogs_krebs·2024-04-09·CVSS 8.1
[HIGH] April’s Patch Tuesday Brings Record Number of Fixes
If only Patch Tuesdays came around infrequently — like total solar eclipse rare — instead of just creeping up on us each month like The Man in the Moon. Although to be fair, it would be tough for Microsoft to eclipse the number of vulnerabilities fixed in this month’s patch batch — a record 147 flaws in Windows and related software.
Yes, you read that right. Microsoft today released updates to address 147 security holes in Windows, Office, Azure, .NET Framework, Visual Studio, SQL Server, DNS Server, Windows Defender, Bitlocker, and Windows Secure Boot.
“This is the largest release from Microsoft this year and the largest since at least 2017,” said Dustin Childs, from Trend Micro’s Zero Day Initiative (ZDI). “As far as I can tell, it’s the largest Patch Tuesday release from Microsoft of
Greynoiseio
Storm⚡Watch: Unplugged
blogs_greynoiseio
Storm⚡Watch: Unplugged
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
2024-04-09
Published
2024-04-30
Added to CISA KEV
Exploited in the wild