← back
CVE-2024-29988

SmartScreen Prompt Security Feature Bypass Vulnerability

CVSS 8.8 HIGHEPSS 45.2%● KEVCWE-693
In short

Microsoft SmartScreen's security prompt can be bypassed by an attacker, allowing malicious files or websites to bypass safety warnings. This means users might not see protective warnings they normally would, putting their systems at risk.

Technical detail

The vulnerability allows an attacker to bypass SmartScreen's prompt security feature through improper validation of user interaction or URL/file handling, potentially via specially crafted inputs. Exploitation requires user interaction but can result in execution of malicious code or navigation to harmful sites without security warnings.

Summary generated and translated by AI from the official description.
SmartScreen Prompt Security Feature Bypass Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →