cbcvebase.
CVE-2024-38213
published 2024-08-13

CVE-2024-38213: Windows Mark of the Web Security Feature Bypass Vulnerability

PriorityP181medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-09-03
Exploited in the wild
EPSS
13.37%
96.0th percentile
Windows Mark of the Web Security Feature Bypass Vulnerability

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.2068010.0.10240.20680
microsoftwindows_10_1607< 10.0.14393.707010.0.14393.7070
microsoftwindows_10_1809< 10.0.17763.593610.0.17763.5936
microsoftwindows_10_21h2< 10.0.19044.452910.0.19044.4529
microsoftwindows_10_22h2< 10.0.19045.452910.0.19045.4529
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.2068010.0.10240.20680
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.707010.0.14393.7070
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.593610.0.17763.5936
microsoftwindows_10_version_21h2>= 10.0.19043.0 < 10.0.19044.452910.0.19044.4529
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.452910.0.19045.4529
microsoftwindows_11_21h2< 10.0.22000.301910.0.22000.3019
microsoftwindows_11_22h2< 10.0.22621.373710.0.22621.3737
microsoftwindows_11_23h2< 10.0.22631.373710.0.22631.3737
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22000.301910.0.22000.3019
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.373710.0.22621.3737
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.373710.0.22631.3737
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.373710.0.22631.3737
microsoftwindows_server_2012< 6.2.9200.249196.2.9200.24919
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.249196.2.9200.24919
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.220236.3.9600.22023
microsoftwindows_server_2016< 10.0.14393.707010.0.14393.7070
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.707010.0.14393.7070
microsoftwindows_server_2019< 10.0.17763.593610.0.17763.5936
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.593610.0.17763.5936

Detection & IOCsextracted from sources · hover to see the quote

othercopy2pwn
pathZone.Identifier
otherZoneId=3
filenamepoc.lnk.zip
  • Monitor for files copied from WebDAV UNC paths (e.g., \\<host>@80\<share>) that are missing the Zone.Identifier alternate data stream (ZoneId=3). Files lacking MotW after being sourced from WebDAV are a strong indicator of CVE-2024-38213 exploitation.
  • Detect use of the Windows search protocol to open WebDAV shares through Windows Explorer, a technique used by DarkGate operators to deliver payloads via copy2pwn.
  • Hunt for malicious .url (Internet Shortcut) or .lnk (Shortcut) files delivered from WebDAV shares with spoofed icons masquerading as legitimate software installers (e.g., Apple iTunes, NVIDIA, Notion).
  • Correlate DarkGate malware activity with WebDAV-based payload delivery; DarkGate operators exploited CVE-2024-38213 in the wild as a zero-day since March 2024 to deploy payloads camouflaged as legitimate software installers.
  • Alert on crafted Windows search queries that restrict the Explorer view to only display specific attacker-controlled files on a WebDAV share, a technique used to socially engineer victims into executing malicious files.
  • ·The vulnerability was patched in the Microsoft June 2024 Patch Tuesday update. Systems without this patch remain vulnerable to copy2pwn attacks where files copied from WebDAV shares bypass MotW protections entirely.
  • ·Microsoft initially forgot to include the CVE-2024-38213 advisory with the June 2024 Patch Tuesday release and also omitted it from July's update, meaning defenders may have missed the patch window.
  • ·Windows historically treats WebDAV shares more like SMB shares than HTTP web servers, meaning MotW is not reliably applied to files accessed via UNC-style WebDAV paths — a systemic design issue underlying this and related CVEs.
  • ·CVE-2024-38213 is part of a cluster of related MotW/SmartScreen bypass vulnerabilities (CVE-2023-36025, CVE-2024-21412, CVE-2024-29988) all centered on WebDAV share abuse; detection and patching should address the full chain.

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
vulncheck8.8HIGH
cisa6.5MEDIUM
vendor_msrc6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.