Windows SmartScreen Security Feature Bypass Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What kind of security feature could be bypassed by successfully exploiting this vulnerability? The attacker would be able to bypass the Open File - Security Warning prompt.
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? The user would have to click on a specially crafted URL to be compromised by the attacker.
🎯 Affected products21
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 Version 1607 for x64-based Systems
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for ARM64-based Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 21H2 for 32-bit Systems
- Windows 10 Version 21H2 for ARM64-based Systems
- Windows 10 Version 21H2 for x64-based Systems
- Windows 10 Version 22H2 for 32-bit Systems
- Windows 10 Version 22H2 for ARM64-based Systems
- Windows 10 Version 22H2 for x64-based Systems
- Windows 11 Version 22H2 for ARM64-based Systems
- Windows 11 Version 22H2 for x64-based Systems
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows Server 2016
- Windows Server 2016 (Server Core installation)
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
✅ Remediation
KB5028168 (Security Update) — fixed build 10.0.17763.4645 KB5028171 (Security Update) — fixed build 10.0.20348.1850 KB5028182 (Security Update) — fixed build 10.0.22000.2176 KB5028166 (Security Update) — fixed build 10.0.19044.3208 KB5028185 (Security Update) — fixed build 10.0.22621.1992 KB5028166 (Security Update) — fixed build 10.0.19045.3208 KB5028169 (Security Update) — fixed build 10.0.14393.6085
🔗 References (12)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32049
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028168
- referencehttps://support.microsoft.com/help/5028168
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028171
- referencehttps://support.microsoft.com/help/5028171
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028182
- referencehttps://support.microsoft.com/help/5028182
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028166
- referencehttps://support.microsoft.com/help/5028166
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028185
- referencehttps://support.microsoft.com/help/5028185
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028169