CVE-2023-24880
Published on: Not Yet Published
Last Modified on: 04/27/2023 07:10:45 PM UTC
Certain versions of Windows 10 1607 from Microsoft contain the following vulnerability:
Windows SmartScreen Security Feature Bypass Vulnerability
- CVE-2023-24880 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 4.4 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | LOW | LOW |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Security Update Guide - Microsoft Security Response Center | msrc.microsoft.com text/html |
![]() |
Related QID Numbers
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Microsoft | Windows 10 1607 | All | All | All | All |
Operating System | Microsoft | Windows 10 1809 | All | All | All | All |
Operating System | Microsoft | Windows 10 20h2 | All | All | All | All |
Operating System | Microsoft | Windows 10 21h2 | All | All | All | All |
Operating System | Microsoft | Windows 10 22h2 | All | All | All | All |
Operating System | Microsoft | Windows 11 21h2 | All | All | All | All |
Operating System | Microsoft | Windows 11 22h2 | All | All | All | All |
Operating System | Microsoft | Windows Server 2016 | - | All | All | All |
Operating System | Microsoft | Windows Server 2019 | - | All | All | All |
Operating System | Microsoft | Windows Server 2022 | - | All | All | All |
- cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_10_20h2:*:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-24880 - Microsoft Windows SmartScreen Security Feature Bypass Vulnerability has been added to the KEV catalog. | 2023-03-14 18:11:53 |
![]() |
msrc.microsoft.com/update-guide/e… msrc.microsoft.com/update-guide/e… | 2023-03-14 18:42:04 |
![]() |
? #CVE-2023-23397, CVE-2023-24880 & CVE-2022-41328 have been added to @CISAgov’s Known Exploited Vulnerabilities Ca… twitter.com/i/web/status/1… | 2023-03-14 18:48:47 |
![]() |
CVE-2023-24880 is a actually bypass to the previous CVE-2022-44698 zero-day exploited by Magniber ransomware and fi… twitter.com/i/web/status/1… | 2023-03-14 19:49:11 |
![]() |
BleepinComputer: CVE-2023-24880 is a actually bypass to the previous CVE-2022-44698 zero-day exploited by Magniber… twitter.com/i/web/status/1… | 2023-03-14 19:50:30 |
![]() |
CVE-2023-24880 | 2023-03-14 18:38:53 |
![]() |
MS-ISAC CYBERSECURITY ADVISORY - Critical Patches Issued for Microsoft Products, March 14, 2023 - PATCH NOW | 2023-03-15 12:44:22 |
![]() |
Ransomware gang exploited a zero-day in Microsoft security feature, Google says | 2023-03-15 15:03:07 |
![]() |
Ransomware gang exploited a zero-day in Microsoft security feature, Google says | 2023-03-15 15:02:34 |
![]() |
CVE-2023-24880 mitigation KB5023697 blocks double-clicking downloads | 2023-03-16 19:23:37 |
![]() |
CVE-2023-24880 mitigation KB5023697 blocks double-clicking downloads | 2023-03-16 19:16:27 |
![]() |
[Sysadmin] CVE-2023-24880 Mitigation KB5023697 Bloques Descargas de doble clic | 2023-04-20 13:38:23 |
![]() |
[Sysadmin] CVE-2023-24880 Mitigation KB5023697 blockiert Doppelklick-Downloads | 2023-04-24 15:44:24 |