CVE-2024-38217
published 2024-09-10CVE-2024-38217: Windows Mark of the Web Security Feature Bypass Vulnerability
PriorityP279medium5.4CVSS 3.1
AVNACLPRNUIRSUCNILAL
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-10-01
Exploited in the wild
EPSS
9.76%
95.0th percentile
Windows Mark of the Web Security Feature Bypass Vulnerability
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.20766 | 10.0.10240.20766 |
| microsoft | windows_10_1607 | < 10.0.14393.7336 | 10.0.14393.7336 |
| microsoft | windows_10_1809 | < 10.0.17763.6293 | 10.0.17763.6293 |
| microsoft | windows_10_21h2 | < 10.0.19044.4894 | 10.0.19044.4894 |
| microsoft | windows_10_22h2 | < 10.0.19045.4894 | 10.0.19045.4894 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.20766 | 10.0.10240.20766 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.7336 | 10.0.14393.7336 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.6293 | 10.0.17763.6293 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.4894 | 10.0.19044.4894 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.4894 | 10.0.19045.4894 |
| microsoft | windows_11_21h2 | < 10.0.22000.3197 | 10.0.22000.3197 |
| microsoft | windows_11_22h2 | < 10.0.22621.4169 | 10.0.22621.4169 |
| microsoft | windows_11_23h2 | < 10.0.22631.4169 | 10.0.22631.4169 |
| microsoft | windows_11_24h2 | < 10.0.26100.1742 | 10.0.26100.1742 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.3197 | 10.0.22000.3197 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.4169 | 10.0.22621.4169 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.4169 | 10.0.22631.4169 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.4169 | 10.0.22631.4169 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.1742 | 10.0.26100.1742 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.27320 | 6.1.7601.27320 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.22870 | 6.0.6003.22870 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.25073 | 6.2.9200.25073 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.22175 | 6.3.9600.22175 |
Detection & IOCsextracted from sources · hover to see the quote
filenameBooks_A0UJKO.pdf%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80.hta↗
- →LNK stomping: detect LNK files with unconventional target paths containing a trailing dot or space appended to the binary name (e.g., 'powershell.exe.') or relative paths (e.g., '.\target.exe'), which trigger Windows Explorer to rewrite the LNK and strip the MotW label. ↗
- →Hunt for HTA files whose filenames contain 26 repeated encoded braille whitespace characters (%E2%A0%80) between a spoofed extension (e.g., .pdf) and the real .hta extension, used to hide the true file type from Windows UI prompts. ↗
- →CVE-2024-38217 has been exploited in LNK stomping attacks since at least 2018; VirusTotal samples exist dating back over six years — hunt for LNK files that cause explorer.exe to rewrite their target path and drop MotW. ↗
- →Monitor for files opened via Internet Explorer (iexplore.exe) launched from specially crafted .url shortcut files, which were used as the initial stage to download malicious HTA payloads in the Void Banshee attack chain. ↗
- →Detect MotW bypass impact: files that bypass Smart App Control and SmartScreen will not trigger the SmartScreen Application Reputation check or the legacy Windows Attachment Services security prompt — alert on execution of downloaded files that lack MotW zone identifier alternate data streams. ↗
- ·The MotW bypass via LNK stomping affects both Smart App Control (Windows 11) and SmartScreen (Windows 10/11 fallback); both security features rely on MotW tagging and are bypassed by this technique. ↗
- ·Microsoft Office Protected View also relies on MotW tagging and is bypassed by this vulnerability, expanding the attack surface beyond just executable files. ↗
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
vulncheck5.4MEDIUM
cisa5.4MEDIUM
vendor_msrc5.4MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-78v4-hxhf-xqqv: Windows Mark of the Web Security Feature Bypass Vulnerability
ghsa_unreviewed·2024-09-10
CVE-2024-38217 [MEDIUM] CWE-693 GHSA-78v4-hxhf-xqqv: Windows Mark of the Web Security Feature Bypass Vulnerability
Windows Mark of the Web Security Feature Bypass Vulnerability
VulnCheck
Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability
vulncheck·2024·CVSS 5.4
CVE-2024-38217 [MEDIUM] CWE-693 Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability
Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability
Microsoft Windows Mark of the Web (MOTW) contains a protection mechanism failure vulnerability that allows an attacker to bypass MOTW-based defenses. This can result in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging.
Affected: Microsoft Windows
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2024-Sep; https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38217; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.zero
CISA
Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability
cisa·2024-09-10·CVSS 5.4
CVE-2024-38217 [MEDIUM] CWE-693 Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability
Vulnerability: Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability
Affected: Microsoft Windows
Microsoft Windows Mark of the Web (MOTW) contains a protection mechanism failure vulnerability that allows an attacker to bypass MOTW-based defenses. This can result in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38217; https://nvd.nist.gov/vuln/detail/CVE-2024-38217
Remediation Due Date: 2024-10-01
Microsoft
Windows Mark of the Web Security Feature Bypass Vulnerability
vendor_msrc·2024-09-10·CVSS 5.4
CVE-2024-38217 [MEDIUM] CWE-693 Windows Mark of the Web Security Feature Bypass Vulnerability
Windows Mark of the Web Security Feature Bypass Vulnerability
FAQ: How could an attacker exploit the vulnerability?
To exploit this vulnerability, an attacker could host a file on an attacker-controlled server, then convince a targeted user to download and open the file. This could allow the attacker to interfere with the Mark of the Web functionality.
Please see Additional information about Mark of the Web for further clarification
FAQ: Windows 11, version 24H2 is not generally available yet. Why are there updates for this version of Windows listed in the Security Updates table?
The new Copilot+ devices that are now publicly available come with Windows 11, version 24H2 installed. Customers with these devices need to know about any vulnerabilities that affect their machine and to install
No detection rules found.
No public exploits indexed.
Bleepingcomputer
CISA warns of Windows flaw used in infostealer malware attacks
blogs_bleepingcomputer·2024-09-16·CVSS 7.5
CVE-2024-38112 [HIGH] CISA warns of Windows flaw used in infostealer malware attacks
## CISA warns of Windows flaw used in infostealer malware attacks
## Sergiu Gatlan
"We released a fix for CVE-2024-38112 in our July 2024 security updates which broke this attack chain," it said. "Customers should both the July 2024 and September 2024 security update to fully protect themselves."
Peter Girnus, the Trend Micro Zero Day Initiative (ZDI) threat researcher who reported the security flaw, told BleepingComputer that Void Banshee hackers exploited it in zero-day attacks to install information-stealing malware.
The vulnerability enables remote attackers to execute arbitrary code on unpatched Windows systems by tricking the targets into visiting a maliciously crafted webpage or opening a malicious file.
"The specific flaw exists within the way Internet Explorer prompts the use
Bleepingcomputer
Windows vulnerability abused braille “spaces” in zero-day attacks
blogs_bleepingcomputer·2024-09-15·CVSS 7.5
CVE-2024-43461 [HIGH] Windows vulnerability abused braille “spaces” in zero-day attacks
## Windows vulnerability abused braille “spaces” in zero-day attacks
## Lawrence Abrams
Void Banshee is an APT hacking group first tracked by Trend Micro that targets organizations in North America, Europe, and Southeast Asia to steal data and for financial gain.
## The CVE-2024-43461 zero-day
In July, Check Point Research and Trend Micro both reported on the same attacks that exploited Windows zero-days to infect devices with the Atlantida info-stealer , used to steal passwords, authentication cookies, and cryptocurrency wallets from infected devices.
The attacks utilized zero-days tracked as CVE-2024-38112 (fixed in July) and CVE-2024-43461 (fixed this month) as part of the attack chain.
The discovery of the CVE-2024-38112 zero-day was attributed to Check Point researcher Haifei Li
Bleepingcomputer
Microsoft September 2024 Patch Tuesday fixes 4 zero-days, 79 flaws
blogs_bleepingcomputer·2024-09-10·CVSS 7.8
[HIGH] Microsoft September 2024 Patch Tuesday fixes 4 zero-days, 79 flaws
## Microsoft September 2024 Patch Tuesday fixes 4 zero-days, 79 flaws
## Lawrence Abrams
30 Elevation of Privilege Vulnerabilities
4 Security Feature Bypass Vulnerabilities
23 Remote Code Execution Vulnerabilities
11 Information Disclosure Vulnerabilities
8 Denial of Service Vulnerabilities
3 Spoofing Vulnerabilities
To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5043076 cumulative update and Windows 10 KB5043064 update .
## Four zero-days disclosed
This month's Patch Tuesday fixes three actively exploited, one of which was publicly disclosed, and another that reintroduces old CVEs so is marked as exploited.
Microsoft classifies a zero-day flaw as one that is publicly disclosed or actively exploited whil
Krebs
Bug Left Some Windows PCs Dangerously Unpatched
blogs_krebs·2024-09-10·CVSS 7.3
CVE-2024-43491 [HIGH] Bug Left Some Windows PCs Dangerously Unpatched
Microsoft Corp. today released updates to fix at least 79 security vulnerabilities in its Windows operating systems and related software, including multiple flaws that are already showing up in active attacks. Microsoft also corrected a critical bug that has caused some Windows 10 PCs to remain dangerously unpatched against actively exploited vulnerabilities for several months this year.
By far the most curious security weakness Microsoft disclosed today has the snappy name of CVE-2024-43491 , which Microsoft says is a vulnerability that led to the rolling back of fixes for some vulnerabilities affecting “optional components” on certain Windows 10 systems produced in 2015. Those include Windows 10 systems that installed the monthly security update for Windows released in March 2024, or ot
Bleepingcomputer
Microsoft fixes Windows Smart App Control zero-day exploited since 2018
blogs_bleepingcomputer·2024-09-10·CVSS 5.4
[MEDIUM] Microsoft fixes Windows Smart App Control zero-day exploited since 2018
## Microsoft fixes Windows Smart App Control zero-day exploited since 2018
## Sergiu Gatlan
"An attacker can craft a malicious file that would evade Mark of the Web (MOTW) defenses, resulting in a limited loss of integrity and availability of security features such as SmartScreen Application Reputation security check and/or the legacy Windows Attachment Services security prompt."
Smart App Control in Windows 11 uses Microsoft's app intelligence services and code integrity features to detect and block potentially harmful apps or binaries.
It replaces SmartScreen in Windows 11, but SmartScreen will still automatically take over if Smart App Control is not enabled to protect against malicious content. Both security features are activated when users try to open files marked with a "Mark of
Trendmicro
The September 2024 Security Update Review
blogs_trendmicro·2024-09-10
The September 2024 Security Update Review
# The September 2024 Security Update Review
Get the September 2023 security update and review.
By: Zero Day Initiative
2024/09/10
Read time: ( words)
Save to Folio
We’ve reached September and the pumpkin spice floats in the air. While they aren’t pumpkin-spiced, Microsoft and Adobe have released their latest spicy security patches – including some zesty 0-days. Take a break from your regular activities and join us as we review the details of their latest security alerts. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for September 2024
For September, Adobe released eight bulletins covering 28 CVEs in Adobe Acrobat and Reader, ColdFusion, Photoshop, Media Encoder, Audition, After Effects, Premier Pro, and Illustrator.
Qualys
Microsoft and Adobe Patch Tuesday, September 2024 Security Update Review
blogs_qualys·2024-09-10
Microsoft and Adobe Patch Tuesday, September 2024 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for September 2024
Adobe Patches for September 2024
Zero-day Vulnerabilities Patched in September Patch Tuesday Edition
Critical Severity Vulnerabilities Patched in September Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Qualys Monthly Webinar Series
Microsoft’s September Patch Tuesday updates are out, addressing a range of vulnerabilities across multiple products. Let’s dive into the key updates and their implications.
## Microsoft Patch Tuesday for September 2024
Microsoft Patch’s Tuesday, September 2024 edition addressed 79 vulnerabilities, including s
Talos
Four zero-days included in group of 79 vulnerabilities Microsoft discloses, including one with 9.8 severity score
blogs_talos·2024-09-10·CVSS 7.8
CVE-2024-38226 [HIGH] Four zero-days included in group of 79 vulnerabilities Microsoft discloses, including one with 9.8 severity score
Microsoft disclosed four vulnerabilities that are actively being exploited in the wild as part of its regular Patch Tuesday security update this week in what’s become a regular occurrence for the company’s patches in 2024.
Two of the zero-day vulnerabilities, CVE-2024-38226 and CVE-2024-38014, exist in the Microsoft Publisher software and Windows Installer, respectively. Last month, Microsoft disclosed six vulnerabilities in its Patch Tuesday that were already being exploited in the wild.
In all, September’s monthly round of patches from Microsoft included 79 vulnerabilities, seven of which are considered critical. In addition to the zero-days disclosed Tuesday, Microsoft also fixed a security issue that had already been publicly disclosed: CVE-2024-38217, a vulnerability in Windows Mark
Qualys
Microsoft & Adobe September 2024 Security Update Review | Qualys
blogs_qualys·2024-09-10
Microsoft & Adobe September 2024 Security Update Review | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for September 2024
- Adobe Patches for September 2024
- Zero-day Vulnerabilities Patched in September Patch Tuesday Edition
- Critical Severity Vulnerabilities Patched in September Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
- Qualys Monthly Webinar Series
Microsoft’s September Patch Tuesday updates are out, addressing a range of vulnerabilities across multiple products. Let’s dive into the key updates and their implications.
## Microsoft Patch Tuesday for September 2024
Microsoft Patch’s Tuesday, September 2024 edition addressed 79 vulnerabilities,
Krebs
Bug Left Some Windows PCs Dangerously Unpatched
blogs_krebs·2024-09-10·CVSS 7.3
CVE-2024-43491 [HIGH] Bug Left Some Windows PCs Dangerously Unpatched
Microsoft Corp. today released updates to fix at least 79 security vulnerabilities in its Windows operating systems and related software, including multiple flaws that are already showing up in active attacks. Microsoft also corrected a critical bug that has caused some Windows 10 PCs to remain dangerously unpatched against actively exploited vulnerabilities for several months this year.
By far the most curious security weakness Microsoft disclosed today has the snappy name of CVE-2024-43491, which Microsoft says is a vulnerability that led to the rolling back of fixes for some vulnerabilities affecting “optional components” on certain Windows 10 systems produced in 2015. Those include Windows 10 systems that installed the monthly security update for Windows released in March 2024, or oth
Talos
Four zero-days included in group of 79 vulnerabilities Microsoft discloses, including one with 9.8 severity score
blogs_talos·2024-09-10·CVSS 7.8
CVE-2024-38226 [HIGH] Four zero-days included in group of 79 vulnerabilities Microsoft discloses, including one with 9.8 severity score
## Four zero-days included in group of 79 vulnerabilities Microsoft discloses, including one with 9.8 severity score
Microsoft disclosed four vulnerabilities that are actively being exploited in the wild as part of its regular Patch Tuesday security update this week in what’s become a regular occurrence for the company’s patches in 2024.
Two of the zero-day vulnerabilities, CVE-2024-38226 and CVE-2024-38014, exist in the Microsoft Publisher software and Windows Installer, respectively. Last month, Microsoft disclosed six vulnerabilities in its Patch Tuesday that were already being exploited in the wild.
In all, September’s monthly round of patches from Microsoft included 79 vulnerabilities, seven of which are considered critical. In addition to the zero-days disclosed Tuesday, Microsoft
Trendmicro
The September 2024 Security Update Review
blogs_trendmicro·2024-09-10·CVSS 7.8
[HIGH] The September 2024 Security Update Review
## The September 2024 Security Update Review
Get the September 2023 security update and review.
By: Zero Day Initiative 2024/09/10 Read time: ( words)
Save to Folio
We’ve reached September and the pumpkin spice floats in the air. While they aren’t pumpkin-spiced, Microsoft and Adobe have released their latest spicy security patches – including some zesty 0-days. Take a break from your regular activities and join us as we review the details of their latest security alerts. If you’d rather watch the full video recap covering the entire release, you can check it out here:
CVE
Title
Severity
CVSS
Public
Exploited
XI
Type
CVE-2024-38217
Windows Mark of the Web Security Feature Bypass Vulnerability
Important
5.4
Yes
Yes
0
SFB
CVE-2024-43491 †
Microsoft Windows Update Remote
Tenable
Microsoft’s September 2024 Patch Tuesday Addresses 79 CVEs (CVE-2024-43491)
blogs_tenable·2024-09-10·CVSS 9.8
[CRITICAL] Microsoft’s September 2024 Patch Tuesday Addresses 79 CVEs (CVE-2024-43491)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Crowdstrike
September 2024 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] September 2024 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2024-09-10
Published
2024-09-10
Added to CISA KEV
Exploited in the wild