Security features bypass in Windows and Windows Server - CVE-2024-21351
Published: February 13, 2024
Windows
Windows Server
Microsoft
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to improper input validation when handling files downloaded from the Internet. A remote attacker can bypass the SmartScreen protection feature and trick the victim into launching a malicious files on the system.
Note, the vulnerability is being actively exploited in the wild.