CISA Known Exploited Vulnerability

CVE-2023-24880 Ransomware

Microsoft · Windows

Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

Date added
BOD 22-01 due date
CWE CWE-863
Ransomware Known

CISA description

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.

Required action

Apply updates per vendor instructions.