- Description
- Windows Mark of the Web Security Feature Bypass Vulnerability
- Source
- secure@microsoft.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Secondary
- Base score
- 5.4
- Impact score
- 2.5
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
- Severity
- MEDIUM
Data from CISA
- Vulnerability name
- Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability
- Exploit added on
- Sep 10, 2024
- Exploit action due
- Oct 1, 2024
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- secure@microsoft.com
- CWE-693
- nvd@nist.gov
- NVD-CWE-noinfo
- Hype score
- Not currently trending
Micropatches for "LNK Stomping" Windows Mark of the Web Security Feature Bypass (CVE-2024-38217) https://t.co/Umlz6NEXeC https://t.co/uZxCLtJ4Gl
@0patch
28 Nov 2024
1187 Impressions
7 Retweets
10 Likes
4 Bookmarks
1 Reply
1 Quote
#Vulnerability #Windows LNK Stomping (CVE-2024-38217): Microsoft Patches Years-Old Zero-Day Flaw https://t.co/ufyhX7ZwEI
@Komodosec
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*",
"vulnerable": true,
"matchCriteriaId": "85DD5735-7C22-4A98-B404-08FEF44A640F",
"versionEndExcluding": "10.0.10240.20766"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*",
"vulnerable": true,
"matchCriteriaId": "83550045-529B-4968-A543-C9D298C0F31D",
"versionEndExcluding": "10.0.10240.20766"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
"vulnerable": true,
"matchCriteriaId": "90027BBC-56AF-4F14-A118-53BBA694A0CD",
"versionEndExcluding": "10.0.14393.7336"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
"vulnerable": true,
"matchCriteriaId": "DFB6CBF4-DA4A-4743-B8A1-3E41FCBEEBEC",
"versionEndExcluding": "10.0.14393.7336"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
"vulnerable": true,
"matchCriteriaId": "ADD534CE-0B4C-43DB-A27C-AC67246D0A87",
"versionEndExcluding": "10.0.17763.6293"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
"vulnerable": true,
"matchCriteriaId": "23DBE62F-98CC-4F76-A841-BB20C5E8075F",
"versionEndExcluding": "10.0.17763.6293"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "30C7FEB1-00AE-42A6-BBAA-A30081BD4A83",
"versionEndExcluding": "10.0.19044.4894"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ACE18049-0E6D-4F64-9702-37D9B4A26A54",
"versionEndExcluding": "10.0.19045.4894"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FF161E1C-AF7E-4F75-86BA-8479D0BA8086",
"versionEndExcluding": "10.0.22000.3197"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "10708C4D-4596-4089-8DDB-5479DE084F64",
"versionEndExcluding": "10.0.22621.4169"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3F9E54F7-0561-49F6-AAD1-B78FF99BBA44",
"versionEndExcluding": "10.0.22631.4169"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*",
"vulnerable": true,
"matchCriteriaId": "6231A772-376C-4ED3-919B-EAD9D1439021",
"versionEndExcluding": "10.0.26100.1742"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
"vulnerable": true,
"matchCriteriaId": "82EA7851-0235-4ACA-8BDB-89243CF2BDA7",
"versionEndExcluding": "10.0.26100.1742"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5F422A8C-2C4E-42C8-B420-E0728037E15C"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*",
"vulnerable": true,
"matchCriteriaId": "AF07A81D-12E5-4B1D-BFF9-C8D08C32FF4F"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A6291C92-7D32-4CC2-B601-FAF5B70F3BFD",
"versionEndExcluding": "10.0.14393.7336"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BD2C9E88-C858-4B3D-A8C5-251DD6B69FD6",
"versionEndExcluding": "10.0.17763.6293"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4399F533-0094-43CF-872E-FC8E4A21A904",
"versionEndExcluding": "10.0.20348.2700"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FCB2DB55-B6D1-4D28-802F-D300BE10E9A0",
"versionEndExcluding": "10.0.25398.1128"
}
],
"operator": "OR"
}
]
}
]