Microsoft Patches SmartScreen Bypass Vulnerability CVE-2024-38213

14 Aug 2024

Microsoft Enhances Security by Addressing Critical Vulnerability

Microsoft has taken significant steps to enhance user security by addressing a Mark of the Web (MotW) security bypass vulnerability, identified as CVE-2024-38213, during the June 2024 Patch Tuesday. This vulnerability had been exploited by attackers as a zero-day, allowing them to circumvent the SmartScreen protection feature, which was first introduced with Windows 8 to safeguard users from potentially harmful software when opening downloaded files.

SmartScreen serves as a critical line of defense, but the vulnerability in question can be exploited remotely by unauthenticated threat actors, albeit with a caveat: it necessitates user interaction. As noted in a security advisory from Microsoft, “An attacker who successfully exploited this vulnerability could bypass the SmartScreen user experience. An attacker must send the user a malicious file and convince them to open it.”

Despite the inherent challenges in successfully executing such an attack, Trend Micro’s security researcher, Peter Girnus, uncovered evidence of the vulnerability being actively exploited in March. Following his report to Microsoft, the flaw was patched in June 2024. However, it is worth mentioning that the advisory detailing this fix was inadvertently omitted from the security updates released that month, as well as from those in July.

Windows SmartScreen Abused in Malware Attacks

According to Dustin Childs, Head of Threat Awareness at Trend Micro’s Zero Day Initiative, the investigation into the March attacks revealed that the DarkGate operators were utilizing this SmartScreen bypass to infect users through seemingly innocuous copy-and-paste operations. “In March 2024, Trend Micro’s Zero Day Initiative Threat Hunting team started analyzing samples connected to the activity carried out by DarkGate operators to infect users through copy-and-paste operations,” Childs explained.

During the March incidents, the DarkGate malware operators leveraged the SmartScreen bypass (CVE-2024-21412) to deploy malicious payloads disguised as installers for legitimate software such as Apple iTunes, Notion, and NVIDIA. As Trend Micro’s researchers delved deeper into the campaign, they also scrutinized how files from WebDAV shares were managed during copy-and-paste actions, leading to the discovery of CVE-2024-38213. This exploit, dubbed “copy2pwn,” allows a file from a WebDAV source to be copied locally without the protective measures typically associated with the Mark of the Web.

Interestingly, CVE-2024-21412 itself was a workaround for another Defender SmartScreen vulnerability, CVE-2023-36025, which had been exploited as a zero-day to deploy Phemedrone malware and was patched in November 2023. The financially motivated hacking group known as Water Hydra, also referred to as DarkCasino, has been implicated in exploiting CVE-2024-21412 to target stock trading Telegram channels and forex trading forums, notably deploying the DarkMe remote access trojan (RAT) on New Year’s Eve.

In addition to these vulnerabilities, Childs highlighted that the same cybercriminal organization had also exploited CVE-2024-29988, another SmartScreen flaw and bypass of CVE-2024-21412, during malware attacks in February. Furthermore, Elastic Security Labs has identified a design flaw in Windows Smart App Control and SmartScreen that allows attackers to launch programs without triggering security warnings, a vulnerability that has been exploited since at least 2018. Elastic Security Labs reported these findings to Microsoft, which indicated that this issue “may be fixed” in a future Windows update.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7508546
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1735263
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
746700
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
495331
downloads

News and reviews for Desktop Windows

Visio 2021 Professional Now $9.97 Until February 8

Microsoft offers Visio 2021 Professional for $9.97, down from $249, with added templates, until February 8.

Read more

Code Vein Offers Stylish Combat, Discounted Editions

Code Vein captivates with anime-style combat and offers discounted editions. Fast-paced action meets fun builds in this cult classic.

Read more

Microsoft Phases Out RC4 in Kerberos for Windows Security

Microsoft to eliminate RC4 in Kerberos by July 2026, enhancing Windows security.

Read more

Highguard Faces Criticism but Shows Potential for Growth

Highguard, launched with controversy, holds potential despite poor reviews. Offering genre innovation, it aims to evolve against negative feedback.

Read more

PS2Recomp Boosts Native PS2 Games with Recompilation

PS2Recomp, a new tool, promises enhanced native PS2 game ports, sparking interest among developers for PC platforms.

Read more

NVIDIA Introduces RTX Remix Logic for Classic Game Mods

NVIDIA's RTX Remix Logic, launched on 2026-01-27, enables dynamic modding of classic PC games with a no-code node-based interface.

Read more

Windows 11 Update KB5074109 Affects Legacy Modems

The Windows 11 update KB5074109 disrupts modems by removing several legacy drivers, causing connectivity issues for select users.

Read more

Anytype Replaces Notion, Obsidian, and Todoist for Unified Workflow

Anytype consolidates Notion, Obsidian, and Todoist functions, reducing context-switching and improving workflow efficiency.

Read more

ReBlade: Cyberpunk Roguelike Announced by ChillyRoom

ReBlade from ChillyRoom and Spiral Up Games announced for PC: cyberpunk roguelike offers high-speed action in a dystopian setting.

Read more

Artorias Battles Elden Ring Bosses in New Video Showcase

Artorias from Dark Souls faces Elden Ring bosses, demonstrating impressive skills in Fights' YouTube video.

Read more