CVE-2024-21351
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Description
CVE-2024-21351 is a Windows SmartScreen Security Feature Bypass vulnerability affecting a broad range of Microsoft Windows versions, from Windows 10 1507 through Windows 11 23H2 and multiple Windows Server editions. The vulnerability is classified as Improper Control of Generation of Code (CWE-94), meaning an attacker can bypass the Windows SmartScreen protection mechanism through a specially crafted file. By convincing a user to interact with a malicious file, an attacker can achieve high integrity impact and limited confidentiality and availability impact without any required privileges. CVE-2024-21351 has been added to CISA's Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild, and its EPSS score of 9.5% (92.7th percentile) indicates a meaningful level of exploitation probability.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:LOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| microsoft | windows 10 1507 | < 10.0.10240.20469 |
| microsoft | windows 10 1607 | < 10.0.14393.6709 |
| microsoft | windows 10 1809 | < 10.0.17763.5458 |
| microsoft | windows 10 21h2 | < 10.0.19044.4046 |
| microsoft | windows 10 22h2 | < 10.0.19045.4046 |
| microsoft | windows 11 21h2 | < 10.0.22000.2777 |
| microsoft | windows 11 22h2 | < 10.0.22621.3155 |
| microsoft | windows 11 23h2 | < 10.0.22631.3155 |
| microsoft | windows server 2016 | - |
| microsoft | windows server 2019 | < 10.0.17763.5458 |
| microsoft | windows server 2022 | < 10.0.20348.2322 |
| microsoft | windows server 2022 23h2 | < 10.0.25398.709 |
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21351(Patch, Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-21351(US Government Resource)
Weakness Type
CWE-94: Improper Control of Generation of Code ('Code Injection')
CWE-94 describes a weakness where software constructs code using externally-influenced input without properly neutralizing elements that can modify the intended code. In CVE-2024-21351, this manifests as Windows SmartScreen failing to properly validate or restrict the execution path of specially crafted files, allowing an attacker to inject or influence code execution in a way that bypasses the SmartScreen security check.
Learn more: CWE-94 — Improper Control of Generation of Code
Impact Analysis
CVE-2024-21351 has a CVSS score of 7.6 (HIGH) and is remotely exploitable over the network with low attack complexity, requiring no special privileges but needing a single user interaction (e.g., opening or previewing a crafted file). Integrity (High): The most significant impact is on integrity — successful exploitation allows an attacker to potentially alter system behavior or install unauthorized code by bypassing SmartScreen warnings. Confidentiality (Low): Some sensitive information may be exposed as a secondary consequence of exploitation. Availability (Low): Minor disruption to availability may result, though this is not the primary risk vector. With confirmed active exploitation in the KEV catalog and an EPSS score placing this vulnerability in the 92.7th percentile, organizations running any affected Windows version without the patch face meaningful risk of compromise via phishing or malicious file delivery.
Exploit Maturity
CVE-2024-21351 has been confirmed as actively exploited in the wild by CISA, with a KEV remediation deadline of March 5, 2024, placing it among the vulnerabilities requiring urgent attention for Microsoft Windows environments. No ransomware association has been confirmed (KEV ransomware flag: Unknown), but the vulnerability's SmartScreen bypass capability makes it a valuable tool in multi-stage attack chains. The EPSS score of 9.5% (92.7th percentile) indicates that exploitation is above average in likelihood compared to the broader CVE population, reflecting real-world attacker interest. No exploit-tagged references were provided in the available data, but the KEV confirmation implies weaponized exploit code is in circulation.
Remediation
- Apply the Microsoft security update for CVE-2024-21351 as directed by the vendor advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21351 — this is CISA's required action for KEV compliance.
- Patch all affected Windows versions: Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), Windows Server 2016, 2019, 2022, and 2022 23H2.
- Ensure Windows SmartScreen is enabled and enforced via Group Policy for all endpoints, as interim hardening against similar bypass techniques.
- Implement email and web gateway controls to block delivery of suspicious file types that could carry crafted payloads exploiting SmartScreen bypass techniques.
- Monitor endpoint detection and response (EDR) telemetry for SmartScreen bypass indicators and review Windows event logs for unusual file execution patterns following the patch.
Technical Details
CVE-2024-21351 is rooted in CWE-94 (Improper Control of Generation of Code), which in the Windows SmartScreen context means that the security subsystem responsible for evaluating the trustworthiness of downloaded or externally-sourced files fails to correctly apply its validation logic against specially constructed inputs. The CVSS vector (AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L) confirms that the attack is network-delivered, requires no privileges, and only needs a single user interaction to trigger — typical of social engineering or phishing-based attack scenarios. The unchanged scope means the impact is contained to the affected Windows component and user context, but the high integrity impact indicates that the attacker can effectively introduce or execute unauthorized code after bypassing the SmartScreen check. This type of bypass is particularly dangerous because it undermines a first-line defense that users often rely on to distinguish safe from unsafe files.
Frequently Asked Questions
Is CVE-2024-21351 being actively exploited?
Yes. CISA has confirmed CVE-2024-21351 as actively exploited in the wild and included it in the Known Exploited Vulnerabilities catalog with a remediation deadline of March 5, 2024. While ransomware usage has not been specifically confirmed, the vulnerability is considered a priority threat for Windows environments.
What products are affected by CVE-2024-21351?
CVE-2024-21351 affects a wide range of Microsoft Windows versions, including Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2022 23H2. Any unpatched system in these ranges is at risk.
How do I fix CVE-2024-21351?
Apply the official Microsoft security patch available through the Microsoft Security Response Center. Organizations should prioritize updating all affected Windows endpoints and servers promptly given the KEV status. Refer to the Remediation section for additional interim mitigation and hardening steps.
How severe is CVE-2024-21351?
CVE-2024-21351 is rated HIGH severity with a CVSS score of 7.6 and an EPSS percentile of 92.7%, reflecting above-average exploitation likelihood. Combined with confirmed active exploitation in the wild, this vulnerability warrants urgent remediation for all organizations running affected Microsoft Windows versions.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.