cbcvebase.
CVE-2024-38217
published 2024-09-10

CVE-2024-38217: Windows Mark of the Web Security Feature Bypass Vulnerability

PriorityP279medium5.4CVSS 3.1
AVNACLPRNUIRSUCNILAL
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-10-01
Exploited in the wild
EPSS
9.76%
95.0th percentile
Windows Mark of the Web Security Feature Bypass Vulnerability

Affected

48 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.2076610.0.10240.20766
microsoftwindows_10_1607< 10.0.14393.733610.0.14393.7336
microsoftwindows_10_1809< 10.0.17763.629310.0.17763.6293
microsoftwindows_10_21h2< 10.0.19044.489410.0.19044.4894
microsoftwindows_10_22h2< 10.0.19045.489410.0.19045.4894
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.2076610.0.10240.20766
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.733610.0.14393.7336
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.629310.0.17763.6293
microsoftwindows_10_version_21h2>= 10.0.19043.0 < 10.0.19044.489410.0.19044.4894
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.489410.0.19045.4894
microsoftwindows_11_21h2< 10.0.22000.319710.0.22000.3197
microsoftwindows_11_22h2< 10.0.22621.416910.0.22621.4169
microsoftwindows_11_23h2< 10.0.22631.416910.0.22631.4169
microsoftwindows_11_24h2< 10.0.26100.174210.0.26100.1742
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22000.319710.0.22000.3197
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.416910.0.22621.4169
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.416910.0.22631.4169
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.416910.0.22631.4169
microsoftwindows_11_version_24h2>= 10.0.26100.0 < 10.0.26100.174210.0.26100.1742
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.273206.1.7601.27320
microsoftwindows_server_2008_service_pack_2>= 6.0.6003.0 < 6.0.6003.228706.0.6003.22870
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.250736.2.9200.25073
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.221756.3.9600.22175

Detection & IOCsextracted from sources · hover to see the quote

filenameBooks_A0UJKO.pdf%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80.hta
  • LNK stomping: detect LNK files with unconventional target paths containing a trailing dot or space appended to the binary name (e.g., 'powershell.exe.') or relative paths (e.g., '.\target.exe'), which trigger Windows Explorer to rewrite the LNK and strip the MotW label.
  • Hunt for HTA files whose filenames contain 26 repeated encoded braille whitespace characters (%E2%A0%80) between a spoofed extension (e.g., .pdf) and the real .hta extension, used to hide the true file type from Windows UI prompts.
  • CVE-2024-38217 has been exploited in LNK stomping attacks since at least 2018; VirusTotal samples exist dating back over six years — hunt for LNK files that cause explorer.exe to rewrite their target path and drop MotW.
  • Monitor for files opened via Internet Explorer (iexplore.exe) launched from specially crafted .url shortcut files, which were used as the initial stage to download malicious HTA payloads in the Void Banshee attack chain.
  • Detect MotW bypass impact: files that bypass Smart App Control and SmartScreen will not trigger the SmartScreen Application Reputation check or the legacy Windows Attachment Services security prompt — alert on execution of downloaded files that lack MotW zone identifier alternate data streams.
  • ·The MotW bypass via LNK stomping affects both Smart App Control (Windows 11) and SmartScreen (Windows 10/11 fallback); both security features rely on MotW tagging and are bypassed by this technique.
  • ·Microsoft Office Protected View also relies on MotW tagging and is bypassed by this vulnerability, expanding the attack surface beyond just executable files.

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
vulncheck5.4MEDIUM
cisa5.4MEDIUM
vendor_msrc5.4MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.