CVE-2024-29988CISA KEV
Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-38831 and CVE-2024-21412 to execute a malicious file.
- Product
- SmartScreen Prompt
- Added to KEV
- 30 Apr 2024
- Federal remediation due
- 21 May 2024
- Known ransomware use
- Not reported