CVE-2023-36584

MEDIUM(5.4)KEV

Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability

Description

CVE-2023-36584 is a security feature bypass vulnerability in Microsoft Windows that affects the Mark of the Web (MotW) mechanism. This flaw allows an attacker to craft files that evade MotW tagging, effectively bypassing security warnings that normally alert users when opening files downloaded from the internet. By exploiting CVE-2023-36584, an attacker can deliver malicious content that appears trustworthy to the operating system, potentially leading to code execution without the expected security prompts. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog with a remediation deadline of December 7, 2023, and its EPSS score of 15.4% (94th percentile) indicates a significant probability of exploitation in the wild.

KEV Information

Vendor
Microsoft
Product
Windows
Date Added
November 16, 2023
Due Date
December 7, 2023
Required Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:LOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
2.5

Affected Products

VendorProductVersion
microsoftwindows 10 1507< 10.0.10240.20232
microsoftwindows 10 1809< 10.0.17763.4974
microsoftwindows 10 21h1< 10.0.19041.3570
microsoftwindows 10 22h2< 10.0.19041.3570
microsoftwindows 11 21h2< 10.0.22000.2538
microsoftwindows 11 22h2< 10.0.22621.2428
microsoftwindows server 2008-; r2
microsoftwindows server 2012-; r2
microsoftwindows server 2016< 10.0.14393.6351
microsoftwindows server 2019< 10.0.17763.4974
microsoftwindows server 2022< 10.0.20348.2031

References

Weakness Type

No specific CWE has been assigned to CVE-2023-36584. The vulnerability is classified as a security feature bypass affecting the Windows Mark of the Web mechanism, which is responsible for tagging files originating from untrusted sources such as the internet or email attachments.

Impact Analysis

CVE-2023-36584 carries a CVSS v3.1 base score of 5.4 (Medium severity), reflecting its moderate but meaningful risk profile. The vulnerability is remotely exploitable over the network with low attack complexity, meaning no special conditions are required for an attacker to deliver a crafted payload. While no authentication is needed to initiate the attack, user interaction is required — the victim must open or interact with a maliciously crafted file. Integrity (Low): The primary impact is on system integrity, as the MotW bypass allows files to be treated as trusted, circumventing built-in security checks such as SmartScreen and Protected View in Microsoft Office. Availability (Low): There is a minor availability impact associated with exploitation. Confidentiality (None): No direct confidentiality impact has been identified. Although the direct impact is rated as low, the real danger lies in the downstream consequences: once MotW is bypassed, additional malicious payloads can execute without the security warnings that would normally protect users, making this vulnerability a valuable component in multi-stage attack chains.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2023-36584 in the wild by adding it to the Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of December 7, 2023. The EPSS score of 15.4% (94th percentile) indicates a notably elevated probability of exploitation compared to most vulnerabilities. While the ransomware association is currently listed as unknown, MotW bypass vulnerabilities are frequently leveraged in phishing campaigns and malware delivery chains, making this a high-priority patching target.

Remediation

  1. Apply Microsoft security updates immediately. Install the patches referenced in the Microsoft Security Response Center advisory for all affected Windows versions. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
  2. Patch all affected Windows versions, including Windows 10 (1507, 1809, 21H1, 22H2), Windows 11 (21H2, 22H2), and Windows Server (2008, 2012, 2016, 2019, 2022). Ensure that both client and server editions receive the update.
  3. Enforce Group Policy settings for file attachment security. Configure Windows to always apply MotW warnings by setting the "Do not preserve zone information in file attachments" policy to Disabled, and strengthen SmartScreen enforcement across the organization.
  4. Monitor for indicators of compromise. Review email gateway and endpoint detection logs for files that may have been delivered without MotW tagging. Investigate any unusual file execution events, particularly from email attachments or web downloads.
  5. Implement defense-in-depth measures. Deploy application whitelisting, restrict macro execution in Microsoft Office via Group Policy, and use endpoint detection and response (EDR) solutions to catch malicious activity that bypasses MotW protections.

Technical Details

CVE-2023-36584 targets the Windows Mark of the Web (MotW) security feature, which is responsible for applying an Alternate Data Stream (ADS) zone identifier to files downloaded from the internet or received via email. When MotW is properly applied, Windows triggers security warnings through mechanisms such as SmartScreen and Protected View before allowing execution or full access to the file. The vulnerability allows an attacker to craft files in a way that prevents the MotW tag from being set or causes it to be stripped, so the operating system treats the file as locally originated and trusted. Attack Vector (Network): The attack is delivered remotely, typically through phishing emails or malicious websites that serve crafted files. Attack Complexity (Low): No special conditions or race conditions are needed — the crafted file alone is sufficient to bypass the MotW mechanism. User Interaction (Required): The victim must open or save the malicious file, but the absence of the expected security warning makes this more likely to succeed. This type of vulnerability is particularly dangerous because it undermines a foundational trust boundary in Windows, enabling follow-on attacks such as macro-based malware, script execution, or binary launches without any protective prompts.

Frequently Asked Questions

Is CVE-2023-36584 being actively exploited?

Yes, CVE-2023-36584 is being actively exploited in the wild. CISA added this vulnerability to the Known Exploited Vulnerabilities catalog with a remediation deadline of December 7, 2023. The EPSS score of 15.4% places it in the 94th percentile, confirming elevated exploitation activity.

What products are affected by CVE-2023-36584?

CVE-2023-36584 affects a wide range of Microsoft Windows versions, including Windows 10 (versions 1507, 1809, 21H1, 22H2), Windows 11 (versions 21H2, 22H2), and Windows Server editions (2008, 2012, 2016, 2019, 2022). Both client and server deployments should be considered at risk.

How do I fix CVE-2023-36584?

Apply the security patches provided by Microsoft through the Microsoft Security Response Center advisory. Ensure all affected Windows client and server versions are updated. Additionally, enforce Group Policy settings for file attachment security and deploy defense-in-depth measures such as application whitelisting and EDR solutions.

How severe is CVE-2023-36584?

CVE-2023-36584 is rated Medium severity with a CVSS v3.1 base score of 5.4. However, its real-world impact is amplified by its role in attack chains — bypassing MotW allows malicious files to execute without security warnings. Its EPSS percentile of 94.5% and active exploitation status make it a high-priority remediation target despite the moderate CVSS score.

CVSS Score

5.4
MEDIUM(5.4)

EPSS Score

EPSS Score3.06%
EPSS Percentile86.5%

Dates

PublishedOctober 10, 2023
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.