CVE-2024-38217CISA KEV
Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Windows Mark of the Web (MOTW) contains a protection mechanism failure vulnerability that allows an attacker to bypass MOTW-based defenses. This can result in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging.
- Product
- Windows
- Added to KEV
- 10 Sep 2024
- Federal remediation due
- 1 Oct 2024
- Known ransomware use
- Not reported