Protection mechanism failure in Microsoft Windows and Windows Server - CVE-2024-29988

 

Protection mechanism failure in Microsoft Windows and Windows Server - CVE-2024-29988

Published: April 9, 2024 / Updated: May 31, 2024


Vulnerability identifier: #VU88316
CSH Severity: High
CVSS v4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-29988
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient implementation of the Mark of the Web (MotW) feature. A remote attacker can supply a malicious file inside an archive to bypass EDR/NDR detection, bypass the SmartScreen prompt and compromise the affected system.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2024-29988

Install updates from vendor's website.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins