CVE-2024-21412

high

Description

Internet Shortcut Files Security Feature Bypass Vulnerability

From the Tenable Blog

Microsoft’s February 2024 Patch Tuesday Addresses 73 CVEs (CVE-2024-21351, CVE-2024-21412)
Microsoft’s February 2024 Patch Tuesday Addresses 73 CVEs (CVE-2024-21351, CVE-2024-21412)

Published: 2024-02-13

Microsoft addresses 73 CVEs, including three zero-day vulnerabilities that were exploited in the wild.

References

https://www.tenable.com/blog/microsoft-patch-tuesday-2024-year-in-review

https://www.securityweek.com/copy2pwn-zero-day-exploited-to-bypass-windows-protections/

https://www.bleepingcomputer.com/news/microsoft/new-windows-smartscreen-bypass-exploited-as-zero-day-since-march/

https://www.darkreading.com/vulnerabilities-threats/cyberattackers-exploit-microsoft-smartscreen-bug-in-stealer-campaign

https://www.fortinet.com/blog/threat-research/exploiting-cve-2024-21412-stealer-campaign-unleashed

https://cyble.com/blog/increase-in-the-exploitation-of-microsoft-smartscreen-vulnerability-cve-2024-21412/?&web_view=true

https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html

https://securelist.com/vulnerability-report-q1-2024/112554/

https://www.tenable.com/blog/microsofts-april-2024-patch-tuesday-addresses-147-cves-cve-2024-29988

https://www.trendmicro.com/en_us/research/24/c/cve-2024-21412--darkgate-operators-exploit-microsoft-windows-sma.html

https://www.infosecurity-magazine.com/news/water-hydras-zero-day-financial/?&web_view=true

https://www.trendmicro.com/en_us/research/24/b/cve202421412-water-hydra-targets-traders-with-windows-defender-s.html

https://www.tenable.com/blog/microsofts-feb-2024-patch-tuesday-cve-2024-21351-cve-2024-21412

https://www.bleepingcomputer.com/news/security/hackers-used-new-windows-defender-zero-day-to-drop-darkme-malware/

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21412

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21412

Details

Source: Mitre, NVD

Published: 2024-02-13

Updated: 2024-11-29

Risk Information

CVSS v2

Base Score: 9.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

Severity: High

CVSS v3

Base Score: 8.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Severity: High