Microsoft Patches SmartScreen Bypass Vulnerability CVE-2024-38213

14 Aug 2024

Microsoft Enhances Security by Addressing Critical Vulnerability

Microsoft has taken significant steps to enhance user security by addressing a Mark of the Web (MotW) security bypass vulnerability, identified as CVE-2024-38213, during the June 2024 Patch Tuesday. This vulnerability had been exploited by attackers as a zero-day, allowing them to circumvent the SmartScreen protection feature, which was first introduced with Windows 8 to safeguard users from potentially harmful software when opening downloaded files.

SmartScreen serves as a critical line of defense, but the vulnerability in question can be exploited remotely by unauthenticated threat actors, albeit with a caveat: it necessitates user interaction. As noted in a security advisory from Microsoft, “An attacker who successfully exploited this vulnerability could bypass the SmartScreen user experience. An attacker must send the user a malicious file and convince them to open it.”

Despite the inherent challenges in successfully executing such an attack, Trend Micro’s security researcher, Peter Girnus, uncovered evidence of the vulnerability being actively exploited in March. Following his report to Microsoft, the flaw was patched in June 2024. However, it is worth mentioning that the advisory detailing this fix was inadvertently omitted from the security updates released that month, as well as from those in July.

Windows SmartScreen Abused in Malware Attacks

According to Dustin Childs, Head of Threat Awareness at Trend Micro’s Zero Day Initiative, the investigation into the March attacks revealed that the DarkGate operators were utilizing this SmartScreen bypass to infect users through seemingly innocuous copy-and-paste operations. “In March 2024, Trend Micro’s Zero Day Initiative Threat Hunting team started analyzing samples connected to the activity carried out by DarkGate operators to infect users through copy-and-paste operations,” Childs explained.

During the March incidents, the DarkGate malware operators leveraged the SmartScreen bypass (CVE-2024-21412) to deploy malicious payloads disguised as installers for legitimate software such as Apple iTunes, Notion, and NVIDIA. As Trend Micro’s researchers delved deeper into the campaign, they also scrutinized how files from WebDAV shares were managed during copy-and-paste actions, leading to the discovery of CVE-2024-38213. This exploit, dubbed “copy2pwn,” allows a file from a WebDAV source to be copied locally without the protective measures typically associated with the Mark of the Web.

Interestingly, CVE-2024-21412 itself was a workaround for another Defender SmartScreen vulnerability, CVE-2023-36025, which had been exploited as a zero-day to deploy Phemedrone malware and was patched in November 2023. The financially motivated hacking group known as Water Hydra, also referred to as DarkCasino, has been implicated in exploiting CVE-2024-21412 to target stock trading Telegram channels and forex trading forums, notably deploying the DarkMe remote access trojan (RAT) on New Year’s Eve.

In addition to these vulnerabilities, Childs highlighted that the same cybercriminal organization had also exploited CVE-2024-29988, another SmartScreen flaw and bypass of CVE-2024-21412, during malware attacks in February. Furthermore, Elastic Security Labs has identified a design flaw in Windows Smart App Control and SmartScreen that allows attackers to launch programs without triggering security warnings, a vulnerability that has been exploited since at least 2018. Elastic Security Labs reported these findings to Microsoft, which indicated that this issue “may be fixed” in a future Windows update.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6585448
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1353795
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
532272
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
457998
downloads

News and reviews for Desktop Windows

Windows 11 Preview Update Boosts Xbox and Recovery Features

Microsoft updates Windows 11 Insider Preview with Xbox enhancements and new recovery options, benefiting testers in Dev and Beta Channels.

Read more

Arc Raiders Tops Steam, Verified for Steam Deck

Arc Raiders, by Embark Studios, verified for Steam Deck, tops Steam's sales charts and achieves high player engagement post-October 30 launch.

Read more

Get Vermintide 2 Free on Steam This Weekend

Vermintide 2 is free on Steam until November 24, 2025. Experience the action-packed co-op shooter and celebrate 10 years of gaming.

Read more

Marvel Contest Champions Expands to PC Gaming via Steam

Marvel Contest Champions moves to PC via Steam, celebrating a rich legacy with new updates.

Read more

Notable Indie Releases in Steam Games 2025

Discover unique 2025 Steam games: from indie horrors to RPG remasters, spanning various price points.

Read more

Hytale Early Access Set for $20 Launch by Hypixel

Hytale early access relaunch at $20; Hypixel aims for original vision despite previous setbacks.

Read more

PUBG: Black Budget Alpha Opens December on Steam

PUBG: Black Budget starts closed alpha in December on Steam for PC. Open to North America, Europe, and Asia. Expected technical feedback.

Read more

Battlemarked Debuts on Steam, Blending D&D with VR

Battlemarked, an adaptation of Demeo and Dungeons & Dragons, is now on Steam, offering VR co-op gameplay with a card-based combat system.

Read more

Snapdragon Chips Enhance Windows Gaming with New Features

Qualcomm refines Windows gaming: Snapdragon Control Panel, enhanced GPU drivers, anti-cheat support, and AVX2 emulation.

Read more

Helldivers 2 Players Rename City 'New York Supreme'

Helldivers 2 users voted to rename York Supreme as New York Supreme. The decision highlights community engagement within the game.

Read more