Windows Smart App Control Vulnerability Exposes Systems to Malicious Attacks

06 Aug 2024

A significant security vulnerability has been uncovered in Windows Smart App Control and SmartScreen, with roots tracing back to at least 2018. This flaw poses a serious risk, as it enables attackers to execute malicious programs on devices without triggering the usual alerts associated with the Mark of the Web (MotW) files, according to experts from Elastic Security Labs.

Exploitation Mechanism

The exploitation revolves around the creation of LNK files that feature modified target paths or internal structures. When these files are opened, Windows Explorer automatically reformats them, a process that inadvertently removes the MotW tag. This reformatting is deceptively simple; a mere space or dot in the target path is sufficient for Windows Explorer to update the file, thus eliminating the security alert typically generated by Smart App Control and SmartScreen.

Interestingly, the flaw has been in active use for several years, with the earliest recorded instance on VirusTotal dating back at least six years. This indicates a long-standing vulnerability that has gone largely unnoticed until now.

Additional Bypass Techniques

Elastic Security Labs has identified further methods that attackers can employ to circumvent the security controls of Smart App Control and SmartScreen. One such method involves the use of code-signing or Extended Validation (EV) signing certificates, which can be utilized to sign malicious payloads that evade detection. Furthermore, attackers may exploit applications that already possess a good reputation, allowing them to slip past security checks unnoticed.

Another tactic includes deploying malicious applications that only activate security checks under specific conditions, thereby reducing the likelihood of detection during initial access.

Recommendations for Security Teams

In light of these findings, Elastic Security Labs emphasizes the need for security teams to conduct thorough scrutiny of downloads within their detection frameworks. They caution against relying solely on the built-in security features of the operating system for comprehensive protection. To assist defenders in identifying this activity until an official patch is released, Elastic Security Labs is providing detection logic and countermeasures.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7508553
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1735314
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
746713
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
495632
downloads

News and reviews for Desktop Windows

Visio 2021 Professional Now $9.97 Until February 8

Microsoft offers Visio 2021 Professional for $9.97, down from $249, with added templates, until February 8.

Read more

Code Vein Offers Stylish Combat, Discounted Editions

Code Vein captivates with anime-style combat and offers discounted editions. Fast-paced action meets fun builds in this cult classic.

Read more

Microsoft Phases Out RC4 in Kerberos for Windows Security

Microsoft to eliminate RC4 in Kerberos by July 2026, enhancing Windows security.

Read more

Highguard Faces Criticism but Shows Potential for Growth

Highguard, launched with controversy, holds potential despite poor reviews. Offering genre innovation, it aims to evolve against negative feedback.

Read more

PS2Recomp Boosts Native PS2 Games with Recompilation

PS2Recomp, a new tool, promises enhanced native PS2 game ports, sparking interest among developers for PC platforms.

Read more

NVIDIA Introduces RTX Remix Logic for Classic Game Mods

NVIDIA's RTX Remix Logic, launched on 2026-01-27, enables dynamic modding of classic PC games with a no-code node-based interface.

Read more

Windows 11 Update KB5074109 Affects Legacy Modems

The Windows 11 update KB5074109 disrupts modems by removing several legacy drivers, causing connectivity issues for select users.

Read more

Anytype Replaces Notion, Obsidian, and Todoist for Unified Workflow

Anytype consolidates Notion, Obsidian, and Todoist functions, reducing context-switching and improving workflow efficiency.

Read more

ReBlade: Cyberpunk Roguelike Announced by ChillyRoom

ReBlade from ChillyRoom and Spiral Up Games announced for PC: cyberpunk roguelike offers high-speed action in a dystopian setting.

Read more

Artorias Battles Elden Ring Bosses in New Video Showcase

Artorias from Dark Souls faces Elden Ring bosses, demonstrating impressive skills in Fights' YouTube video.

Read more