ID:9619 - Exploit for Security features bypass in Windows and Windows Server - CVE-2024-21412

 
Main Vulnerability Database Exploits ID:9619 - Exploit for Security features bypass in Windows and Windows Server - CVE-2024-21412

ID:9619 - Exploit for Security features bypass in Windows and Windows Server - CVE-2024-21412

Published: March 22, 2024


Vulnerability identifier: #VU86398
Vulnerability risk: Critical
CVE-ID: CVE-2024-21412
CWE-ID: CWE-254
Exploitation vector: Remote access
Vulnerable software:
Windows
Windows Server

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to improper input validation when handling Internet shortcut files. A remote attacker can trick the victim into clicking on a specially crafted shortcut file and execute arbitrary code on the system.

Note, the vulnerability is being actively exploited in the wild.

Remediation

Install updates from vendor's website.