CVE-2024-38213
published 2024-08-13CVE-2024-38213: Windows Mark of the Web Security Feature Bypass Vulnerability
PriorityP181medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-09-03
Exploited in the wild
EPSS
13.37%
96.0th percentile
Windows Mark of the Web Security Feature Bypass Vulnerability
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.20680 | 10.0.10240.20680 |
| microsoft | windows_10_1607 | < 10.0.14393.7070 | 10.0.14393.7070 |
| microsoft | windows_10_1809 | < 10.0.17763.5936 | 10.0.17763.5936 |
| microsoft | windows_10_21h2 | < 10.0.19044.4529 | 10.0.19044.4529 |
| microsoft | windows_10_22h2 | < 10.0.19045.4529 | 10.0.19045.4529 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.20680 | 10.0.10240.20680 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.7070 | 10.0.14393.7070 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.5936 | 10.0.17763.5936 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.4529 | 10.0.19044.4529 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.4529 | 10.0.19045.4529 |
| microsoft | windows_11_21h2 | < 10.0.22000.3019 | 10.0.22000.3019 |
| microsoft | windows_11_22h2 | < 10.0.22621.3737 | 10.0.22621.3737 |
| microsoft | windows_11_23h2 | < 10.0.22631.3737 | 10.0.22631.3737 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.3019 | 10.0.22000.3019 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.3737 | 10.0.22621.3737 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.3737 | 10.0.22631.3737 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.3737 | 10.0.22631.3737 |
| microsoft | windows_server_2012 | < 6.2.9200.24919 | 6.2.9200.24919 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.24919 | 6.2.9200.24919 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.22023 | 6.3.9600.22023 |
| microsoft | windows_server_2016 | < 10.0.14393.7070 | 10.0.14393.7070 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.7070 | 10.0.14393.7070 |
| microsoft | windows_server_2019 | < 10.0.17763.5936 | 10.0.17763.5936 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.5936 | 10.0.17763.5936 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for files copied from WebDAV UNC paths (e.g., \\<host>@80\<share>) that are missing the Zone.Identifier alternate data stream (ZoneId=3). Files lacking MotW after being sourced from WebDAV are a strong indicator of CVE-2024-38213 exploitation. ↗
- →Detect use of the Windows search protocol to open WebDAV shares through Windows Explorer, a technique used by DarkGate operators to deliver payloads via copy2pwn. ↗
- →Hunt for malicious .url (Internet Shortcut) or .lnk (Shortcut) files delivered from WebDAV shares with spoofed icons masquerading as legitimate software installers (e.g., Apple iTunes, NVIDIA, Notion). ↗
- →Correlate DarkGate malware activity with WebDAV-based payload delivery; DarkGate operators exploited CVE-2024-38213 in the wild as a zero-day since March 2024 to deploy payloads camouflaged as legitimate software installers. ↗
- →Alert on crafted Windows search queries that restrict the Explorer view to only display specific attacker-controlled files on a WebDAV share, a technique used to socially engineer victims into executing malicious files. ↗
- ·The vulnerability was patched in the Microsoft June 2024 Patch Tuesday update. Systems without this patch remain vulnerable to copy2pwn attacks where files copied from WebDAV shares bypass MotW protections entirely. ↗
- ·Microsoft initially forgot to include the CVE-2024-38213 advisory with the June 2024 Patch Tuesday release and also omitted it from July's update, meaning defenders may have missed the patch window. ↗
- ·Windows historically treats WebDAV shares more like SMB shares than HTTP web servers, meaning MotW is not reliably applied to files accessed via UNC-style WebDAV paths — a systemic design issue underlying this and related CVEs. ↗
- ·CVE-2024-38213 is part of a cluster of related MotW/SmartScreen bypass vulnerabilities (CVE-2023-36025, CVE-2024-21412, CVE-2024-29988) all centered on WebDAV share abuse; detection and patching should address the full chain. ↗
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
vulncheck8.8HIGH
cisa6.5MEDIUM
vendor_msrc6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
cisa·2024-08-13·CVSS 6.5
CVE-2024-38213 [MEDIUM] CWE-693 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Vulnerability: Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Affected: Microsoft Windows
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience via a malicious file.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38213; https://nvd.nist.gov/vuln/detail/CVE-2024-38213
Remediation Due Date: 2024-09-03
Microsoft
Windows Mark of the Web Security Feature Bypass Vulnerability
vendor_msrc·2024-08-13·CVSS 6.5
CVE-2024-38213 [MEDIUM] CWE-693 Windows Mark of the Web Security Feature Bypass Vulnerability
Windows Mark of the Web Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could bypass the SmartScreen user experience.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker must send the user a malicious file and convince them to open it.
Windows Mark of the Web (MOTW): Windows Mark of the Web (MOTW)
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:Yes;Latest Software Release:Exploitation Detected
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5039217
Referen
GHSA
GHSA-x6j5-wvpj-p4qv: Windows Mark of the Web Security Feature Bypass Vulnerability
ghsa_unreviewed·2024-08-13
CVE-2024-38213 [MEDIUM] CWE-693 GHSA-x6j5-wvpj-p4qv: Windows Mark of the Web Security Feature Bypass Vulnerability
Windows Mark of the Web Security Feature Bypass Vulnerability
VulnCheck
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
vulncheck·2024·CVSS 6.5
CVE-2024-38213 [MEDIUM] CWE-693 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience via a malicious file.
Affected: Microsoft Windows
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2024-Aug; https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38213; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.zerodayinitiative.com/blog/2024/8/14/cve-2024-38213-copy2pwn-exploit-evades-windows-web-protections; https://www.zerodayinitiative.com/blog/2025/1/8/zdi-threat-
VulnCheck
Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability
vulncheck·2024·CVSS 7.8
CVE-2024-29988 [HIGH] CWE-693 Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability
Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability
Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-38831 and CVE-2024-21412 to execute a malicious file.
Affected: Microsoft SmartScreen Prompt
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://www.zerodayinitiative.com/blog/2024/4/9/the-april-2024-security-updates-review; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.zerodayinitiative.com/blog/2024/8/14/cve-2024-38213-copy2pwn-exploit-evades-windows-web-protections; http
VulnCheck
Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability
vulncheck·2024·CVSS 8.1
CVE-2024-21412 [HIGH] CWE-693 Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability
Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability
Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass.
Affected: Microsoft Windows
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2024-Feb; https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21412; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.trendmicro.com/en_us/research/24/b/cve202421412-water-hydra-targets-traders-with-windows-defender-s.html; https://www.trendmicro.com/en_us/research/24/c/c
VulnCheck
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
vulncheck·2023·CVSS 8.8
CVE-2023-36025 [HIGH] Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts.
Affected: Microsoft Windows
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2023-Nov; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://twitter.com/ffforward/status/1726540034462159165; https://www.trendmicro.com/en_us/research/24/a/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-steal.html; https://uni
No detection rules found.
No public exploits indexed.
Bleepingcomputer
7-Zip fixes bug that bypasses Windows MoTW security warnings, patch now
blogs_bleepingcomputer·2025-01-21·CVSS 7.0
[HIGH] 7-Zip fixes bug that bypasses Windows MoTW security warnings, patch now
## 7-Zip fixes bug that bypasses Windows MoTW security warnings, patch now
## Sergiu Gatlan
A high-severity vulnerability in the 7-Zip file archiver allows attackers to bypass the Mark of the Web (MotW) Windows security feature and execute code on users' computers when extracting malicious files from nested archives.
7-Zip added support for MotW in June 2022 , starting with version 22.00. Since then, it has automatically added MotW flags (special 'Zone.Id' alternate data streams) to all files extracted from downloaded archives.
This flag informs the operating system, web browsers, and other applications that files may come from untrusted sources and should be treated with caution.
As a result, when double-clicking risky files extracted using 7-Zip, users will be warned that opening o
Tenable
Microsoft Patch Tuesday 2024 Year in Review
blogs_tenable·2024-12-10
Microsoft Patch Tuesday 2024 Year in Review
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Microsoft’s September 2024 Patch Tuesday Addresses 79 CVEs (CVE-2024-43491)
blogs_tenable·2024-09-10·CVSS 9.8
[CRITICAL] Microsoft’s September 2024 Patch Tuesday Addresses 79 CVEs (CVE-2024-43491)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
CVE-2024-38213: Copy2Pwn Exploit Evades Windows Web Protections
blogs_trendmicro·2024-08-15·CVSS 8.1
CVE-2024-38213 [HIGH] CVE-2024-38213: Copy2Pwn Exploit Evades Windows Web Protections
## CVE-2024-38213: Copy2Pwn Exploit Evades Windows Web Protections
Learn how the cve-2024-38213 and copy2pwn exploit evades Windows web protections.
By: Peter Girnus 2024/08/15 Read time: ( words)
Save to Folio
Zero Day Initiative threat researchers discovered CVE-2024-38213, a simple and effective way to bypass Windows mark-of-the-web protections leading to remote code execution.
In March 2024, Trend Micro’s Zero Day Initiative Threat Hunting team started analyzing samples connected to the activity carried out by DarkGate operators to infect users through copy-and-paste operations. This DarkGate campaign was an update from a previous campaign in which the DarkGate operators were exploiting a zero-day vulnerability, CVE-2024-21412 , which we disclosed to Microsoft earlier this year.
Trendmicro
CVE-2024-38213: Copy2Pwn Exploit Evades Windows Web Protections
blogs_trendmicro·2024-08-15·CVSS 8.1
CVE-2024-38213 [HIGH] CVE-2024-38213: Copy2Pwn Exploit Evades Windows Web Protections
# CVE-2024-38213: Copy2Pwn Exploit Evades Windows Web Protections
Learn how the cve-2024-38213 and copy2pwn exploit evades Windows web protections.
By: Peter Girnus
2024/08/15
Read time: ( words)
Save to Folio
Zero Day Initiative threat researchers discovered CVE-2024-38213, a simple and effective way to bypass Windows mark-of-the-web protections leading to remote code execution.
In March 2024, Trend Micro’s Zero Day Initiative Threat Hunting team started analyzing samples connected to the activity carried out by DarkGate operators to infect users through copy-and-paste operations. This DarkGate campaign was an update from a previous campaign in which the DarkGate operators were exploiting a zero-day vulnerability, CVE-2024-21412, which we disclosed to Microsoft earlier this year.
T
Bleepingcomputer
New Windows SmartScreen bypass exploited as zero-day since March
blogs_bleepingcomputer·2024-08-13·CVSS 8.1
[HIGH] New Windows SmartScreen bypass exploited as zero-day since March
## New Windows SmartScreen bypass exploited as zero-day since March
## Sergiu Gatlan
"An attacker who successfully exploited this vulnerability could bypass the SmartScreen user experience. An attacker must send the user a malicious file and convince them to open it," Redmond explains in a security advisory published on Tuesday.
Despite the increased difficulty in exploiting it, Trend Micro security researcher Peter Girnus discovered that the vulnerability was being exploited in the wild in March. Girnus reported the attacks to Microsoft, who patched the flaw during the June 2024 Patch Tuesday. However, the company forgot to include the advisory with that month's security updates (or with July's).
"In March 2024, Trend Micro's Zero Day Initiative Threat Hunting team started analyzing s
Trendmicro
The August 2024 Security Update Review
blogs_trendmicro·2024-08-13·CVSS 6.7
[MEDIUM] The August 2024 Security Update Review
## The August 2024 Security Update Review
Get the August 2024 security update and review.
By: Dustin Childs 2024/08/13 Read time: ( words)
Save to Folio
I have successfully survived Summer Hacker Camp, and I hope you have too. And we return just in time for Patch Tuesday and a new crop of 0-days as Microsoft and Adobe have released their regularly scheduled updates. Take a break from your regular activities and join us as we review the details of their latest security alerts. If you’d rather watch the full video recap covering the entire release, you can check it out here:
CVE
Title
Severity
CVSS
Public
Exploited
Type
CVE-2024-38189
Microsoft Project Remote Code Execution Vulnerability
Important
8.8
No
Yes
RCE
CVE-2024-38178
Scripting Engine Memory Corruption Vulnerabil
Krebs
Six 0-Days Lead Microsoft’s August 2024 Patch Push
blogs_krebs·2024-08-13·CVSS 7.0
[HIGH] Six 0-Days Lead Microsoft’s August 2024 Patch Push
Microsoft today released updates to fix at least 90 security vulnerabilities in Windows and related software, including a whopping six zero-day flaws that are already being actively exploited by attackers.
Image: Shutterstock.
This month’s bundle of update joy from Redmond includes patches for security holes in Office , .NET , Visual Studio , Azure , Co-Pilot , Microsoft Dynamics , Teams , Secure Boot, and of course Windows itself. Of the six zero-day weaknesses Microsoft addressed this month, half are local privilege escalation vulnerabilities — meaning they are primarily useful for attackers when combined with other flaws or access.
CVE-2024-38106 , CVE-2024-38107 and CVE-2024-38193 all allow an attacker to gain SYSTEM level privileges on a vulnerable machine, although the vulnerabili
Qualys
Microsoft and Adobe Patch Tuesday, August 2024 Security Update Review
blogs_qualys·2024-08-13·CVSS 6.7
[MEDIUM] Microsoft and Adobe Patch Tuesday, August 2024 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for August 2024
Adobe Patches for August 2024
Zero-day Vulnerabilities Patched in August Patch Tuesday Edition
Critical Severity Vulnerabilities Patched in August Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Qualys Monthly Webinar Series
Microsoft’s August Patch Tuesday updates are out, and they address a range of vulnerabilities across multiple products. Let’s dive into the key updates and their implications.
## Microsoft Patch Tuesday for August 2024
Microsoft Patch’s Tuesday, August 202
Tenable
Microsoft’s August 2024 Patch Tuesday Addresses 88 CVEs
blogs_tenable·2024-08-13
Microsoft’s August 2024 Patch Tuesday Addresses 88 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Microsoft & Adobe August 2024 Patch Tuesday Updates | Qualys
blogs_qualys·2024-08-13·CVSS 6.7
[MEDIUM] Microsoft & Adobe August 2024 Patch Tuesday Updates | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for August 2024
- Adobe Patches for August 2024
- Zero-day Vulnerabilities Patched in August Patch Tuesday Edition
- Critical Severity Vulnerabilities Patched in August Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- Qualys Monthly Webinar Series
Microsoft’s August Patch Tuesday updates are out, and they address a range of vulnerabilities across multiple products. Let’s dive into the key updates and their implications.
## Microsoft Patch Tuesday for August 2024
Microsoft Patch’s Tuesda
Bleepingcomputer
Microsoft August 2024 Patch Tuesday fixes 9 zero-days, 6 exploited
blogs_bleepingcomputer·2024-08-13·CVSS 7.5
[HIGH] Microsoft August 2024 Patch Tuesday fixes 9 zero-days, 6 exploited
## Microsoft August 2024 Patch Tuesday fixes 9 zero-days, 6 exploited
## Lawrence Abrams
36 Elevation of Privilege Vulnerabilities
4 Security Feature Bypass Vulnerabilities
28 Remote Code Execution Vulnerabilities
8 Information Disclosure Vulnerabilities
6 Denial of Service Vulnerabilities
7 Spoofing Vulnerabilities
The number of bugs listed above do not include Microsoft Edge flaws that were disclosed earlier this month.
To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5041585 update and Windows 10 KB5041580 update .
## Ten zero-days disclosed
This month's Patch Tuesday fixes six actively exploited and three other publicly disclosed zero-day vulnerabilities. Another publicly disclosed zero-day remains unf
Krebs
Six 0-Days Lead Microsoft’s August 2024 Patch Push
blogs_krebs·2024-08-13·CVSS 7.0
[HIGH] Six 0-Days Lead Microsoft’s August 2024 Patch Push
Microsoft today released updates to fix at least 90 security vulnerabilities in Windows and related software, including a whopping six zero-day flaws that are already being actively exploited by attackers.
This month’s bundle of update joy from Redmond includes patches for security holes in Office, .NET, Visual Studio, Azure, Co-Pilot, Microsoft Dynamics, Teams, Secure Boot, and of course Windows itself. Of the six zero-day weaknesses Microsoft addressed this month, half are local privilege escalation vulnerabilities — meaning they are primarily useful for attackers when combined with other flaws or access.
CVE-2024-38106, CVE-2024-38107 and CVE-2024-38193 all allow an attacker to gain SYSTEM level privileges on a vulnerable machine, although the vulnerabilities reside in different parts
Trendmicro
The August 2024 Security Update Review
blogs_trendmicro·2024-08-13
The August 2024 Security Update Review
# The August 2024 Security Update Review
Get the August 2024 security update and review.
By: Dustin Childs
2024/08/13
Read time: ( words)
Save to Folio
I have successfully survived Summer Hacker Camp, and I hope you have too. And we return just in time for Patch Tuesday and a new crop of 0-days as Microsoft and Adobe have released their regularly scheduled updates. Take a break from your regular activities and join us as we review the details of their latest security alerts. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for August 2024
For August, Adobe released 11 security bulletins addressing 71 CVEs in Adobe Illustrator. Dimension, Photoshop, InDesign, Acrobat and Reader, Bridge, Substance 3D Stager, Commerce, InC
Crowdstrike
August 2024 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] August 2024 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Crowdstrike
Featured Articles
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Featured Articles
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
August 2024 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] August 2024 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2024-08-13
Published
2024-08-13
Added to CISA KEV
Exploited in the wild