News Security Technology

Microsoft Patches 6-Year-Old SmartScreen Flaw Exploited By Hackers

Zero Trust Security
Zero-day vulnerability has been exploited since 2018, allowing threat actors to bypass Windows security features

Microsoft has addressed a critical vulnerability in its Windows Smart App Control and SmartScreen, which has been actively exploited in cyberattacks as a zero-day flaw since 2018. The flaw, now tracked as CVE-2024-38217, allowed attackers to bypass Smart App Control and the Mark of the Web (MotW) security feature, launching untrusted or potentially dangerous binaries and applications without triggering security warnings.

In a security advisory published today, Microsoft detailed how threat actors could host malicious files on their servers and deceive users into downloading and opening them. This exploitation method enabled attackers to interfere with the Mark of the Web functionality, which is critical for Windows’ security checks. According to Microsoft, the flaw could result in the loss of key security features, including SmartScreen’s Application Reputation checks and Windows’ legacy Attachment Services prompt.

Smart App Control, introduced in Windows 11, works alongside Microsoft’s app intelligence services and code integrity features to detect harmful apps. While it replaces SmartScreen in Windows 11, SmartScreen remains active if Smart App Control is disabled, ensuring protection against malicious content.

Last month, Elastic Security Labs disclosed CVE-2024-38217, highlighting how attackers exploited it through a method called “LNK stomping,” a flaw in handling LNK files. By manipulating file paths, attackers could bypass Smart App Control’s defenses and launch untrusted apps without triggering security prompts.

Elastic Security Labs revealed that this vulnerability may have been exploited for years, with VirusTotal showing the earliest evidence of the flaw dating back over six years. The findings were shared with Microsoft, which acknowledged the issue and confirmed a fix in a future Windows update.

Leave a Reply

Your email address will not be published. Required fields are marked *