CVE-2024-21412

Published Feb 13, 2024

Last updated 7 months ago

Overview

Description
Internet Shortcut Files Security Feature Bypass Vulnerability
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_21h2, windows_11_22h2, windows_11_23h2, windows_server_2019, windows_server_2022, windows_server_2022_23h2

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.1
Impact score
5.2
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability
Exploit added on
Feb 13, 2024
Exploit action due
Mar 5, 2024
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weaknesses

secure@microsoft.com
CWE-693
nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending
  1. CVE-2024-21412: Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass. Status: ✅ Confirmed exploited in the wild Date added: 2024-02-13 Required action: Apply mitigations per vendor instructions or…

    @lyrie_ai

    3 May 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. 🚨 Defender Zero-Day Alert! CVE-2024-21412 bypasses SmartScreen to execute malware. Protect your perimeter with Wiseman Infosec’s EDR tuning & threat hunting. 📧 sales@wisemaninfosec.com 🌐 https://t.co/Tr06DAiGko #CyberSecurity #Infosec #ZeroDay #WisemanInfosec #S

    @officialwisema

    15 Apr 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. https://t.co/n6DUYxNkUc Windowsのショートカットファイルを悪用したセキュリティ脆弱性(CVE-2024-21412)に関するレポートです。悪用されるとセキュリティ機能がバイパスされる恐れがあるため、速やかなパッチ適用

    @Anti_Ch_PCgc

    1 Apr 2026

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 【独自】米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性が更新。以下脆弱性でランサムウェアによる悪用が確認された。 - WindowsのCVE-2024-21412 - IvantiのCVE-2024-21893, CVE-2023-46805, CV

    @__kokumoto

    8 Oct 2025

    1070 Impressions

    3 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  5. Actively exploited CVE : CVE-2024-21412

    @transilienceai

    21 Nov 2024

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations