CVE-2024-38213

Published Aug 13, 2024

Last updated 7 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-38213, also known as Copy2Pwn, is a zero-day vulnerability that allows attackers to bypass the Mark of the Web (MotW) security feature in Windows. MotW typically flags files downloaded from the internet or copied from specific network locations, prompting cautious handling by the operating system. This vulnerability, however, permits files copied from WebDAV shares to bypass this check, making them appear as if they originated locally. This can lead to the execution of malicious code as security measures that rely on MotW, such as Windows Defender SmartScreen and Office Protected View, are effectively neutralized. This vulnerability was discovered in August 2024 and was actively exploited before a patch was available. It affects how Windows handles files copied from WebDAV, a type of web-based file-sharing service. Even with security warnings present when dragging and dropping files from a network folder, the MotW flag is not applied, leaving systems vulnerable. The exploit has been used in targeted email campaigns and other attacks to deliver malware and steal sensitive data. While Microsoft released a patch in July 2024, subsequent analysis revealed flaws in the initial fix, highlighting the ongoing challenge of addressing such vulnerabilities.

Description
Windows Mark of the Web Security Feature Bypass Vulnerability
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_10_1507, windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_21h2, windows_11_22h2, windows_11_23h2, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2022_23h2

Risk scores

CVSS 3.1

Type
Secondary
Base score
6.5
Impact score
3.6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Severity
MEDIUM

Known exploits

Data from CISA

Vulnerability name
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Exploit added on
Aug 13, 2024
Exploit action due
Sep 3, 2024
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weaknesses

secure@microsoft.com
CWE-693
nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending

Configurations