CVE-2024-21351

HIGH(7.6)KEVElevated Risk

Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

Description

CVE-2024-21351 is a Windows SmartScreen Security Feature Bypass vulnerability affecting a broad range of Microsoft Windows versions, from Windows 10 1507 through Windows 11 23H2 and multiple Windows Server editions. The vulnerability is classified as Improper Control of Generation of Code (CWE-94), meaning an attacker can bypass the Windows SmartScreen protection mechanism through a specially crafted file. By convincing a user to interact with a malicious file, an attacker can achieve high integrity impact and limited confidentiality and availability impact without any required privileges. CVE-2024-21351 has been added to CISA's Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild, and its EPSS score of 9.5% (92.7th percentile) indicates a meaningful level of exploitation probability.

KEV Information

Vendor
Microsoft
Product
Windows
Date Added
February 13, 2024
Due Date
March 5, 2024
Required Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:LOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
4.7

CWEs

Affected Products

VendorProductVersion
microsoftwindows 10 1507< 10.0.10240.20469
microsoftwindows 10 1607< 10.0.14393.6709
microsoftwindows 10 1809< 10.0.17763.5458
microsoftwindows 10 21h2< 10.0.19044.4046
microsoftwindows 10 22h2< 10.0.19045.4046
microsoftwindows 11 21h2< 10.0.22000.2777
microsoftwindows 11 22h2< 10.0.22621.3155
microsoftwindows 11 23h2< 10.0.22631.3155
microsoftwindows server 2016-
microsoftwindows server 2019< 10.0.17763.5458
microsoftwindows server 2022< 10.0.20348.2322
microsoftwindows server 2022 23h2< 10.0.25398.709

References

Weakness Type

CWE-94: Improper Control of Generation of Code ('Code Injection')

CWE-94 describes a weakness where software constructs code using externally-influenced input without properly neutralizing elements that can modify the intended code. In CVE-2024-21351, this manifests as Windows SmartScreen failing to properly validate or restrict the execution path of specially crafted files, allowing an attacker to inject or influence code execution in a way that bypasses the SmartScreen security check.

Learn more: CWE-94 — Improper Control of Generation of Code

Impact Analysis

CVE-2024-21351 has a CVSS score of 7.6 (HIGH) and is remotely exploitable over the network with low attack complexity, requiring no special privileges but needing a single user interaction (e.g., opening or previewing a crafted file). Integrity (High): The most significant impact is on integrity — successful exploitation allows an attacker to potentially alter system behavior or install unauthorized code by bypassing SmartScreen warnings. Confidentiality (Low): Some sensitive information may be exposed as a secondary consequence of exploitation. Availability (Low): Minor disruption to availability may result, though this is not the primary risk vector. With confirmed active exploitation in the KEV catalog and an EPSS score placing this vulnerability in the 92.7th percentile, organizations running any affected Windows version without the patch face meaningful risk of compromise via phishing or malicious file delivery.

Exploit Maturity

CVE-2024-21351 has been confirmed as actively exploited in the wild by CISA, with a KEV remediation deadline of March 5, 2024, placing it among the vulnerabilities requiring urgent attention for Microsoft Windows environments. No ransomware association has been confirmed (KEV ransomware flag: Unknown), but the vulnerability's SmartScreen bypass capability makes it a valuable tool in multi-stage attack chains. The EPSS score of 9.5% (92.7th percentile) indicates that exploitation is above average in likelihood compared to the broader CVE population, reflecting real-world attacker interest. No exploit-tagged references were provided in the available data, but the KEV confirmation implies weaponized exploit code is in circulation.

Remediation

  1. Apply the Microsoft security update for CVE-2024-21351 as directed by the vendor advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21351 — this is CISA's required action for KEV compliance.
  2. Patch all affected Windows versions: Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), Windows Server 2016, 2019, 2022, and 2022 23H2.
  3. Ensure Windows SmartScreen is enabled and enforced via Group Policy for all endpoints, as interim hardening against similar bypass techniques.
  4. Implement email and web gateway controls to block delivery of suspicious file types that could carry crafted payloads exploiting SmartScreen bypass techniques.
  5. Monitor endpoint detection and response (EDR) telemetry for SmartScreen bypass indicators and review Windows event logs for unusual file execution patterns following the patch.

Technical Details

CVE-2024-21351 is rooted in CWE-94 (Improper Control of Generation of Code), which in the Windows SmartScreen context means that the security subsystem responsible for evaluating the trustworthiness of downloaded or externally-sourced files fails to correctly apply its validation logic against specially constructed inputs. The CVSS vector (AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L) confirms that the attack is network-delivered, requires no privileges, and only needs a single user interaction to trigger — typical of social engineering or phishing-based attack scenarios. The unchanged scope means the impact is contained to the affected Windows component and user context, but the high integrity impact indicates that the attacker can effectively introduce or execute unauthorized code after bypassing the SmartScreen check. This type of bypass is particularly dangerous because it undermines a first-line defense that users often rely on to distinguish safe from unsafe files.

Frequently Asked Questions

Is CVE-2024-21351 being actively exploited?

Yes. CISA has confirmed CVE-2024-21351 as actively exploited in the wild and included it in the Known Exploited Vulnerabilities catalog with a remediation deadline of March 5, 2024. While ransomware usage has not been specifically confirmed, the vulnerability is considered a priority threat for Windows environments.

What products are affected by CVE-2024-21351?

CVE-2024-21351 affects a wide range of Microsoft Windows versions, including Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2022 23H2. Any unpatched system in these ranges is at risk.

How do I fix CVE-2024-21351?

Apply the official Microsoft security patch available through the Microsoft Security Response Center. Organizations should prioritize updating all affected Windows endpoints and servers promptly given the KEV status. Refer to the Remediation section for additional interim mitigation and hardening steps.

How severe is CVE-2024-21351?

CVE-2024-21351 is rated HIGH severity with a CVSS score of 7.6 and an EPSS percentile of 92.7%, reflecting above-average exploitation likelihood. Combined with confirmed active exploitation in the wild, this vulnerability warrants urgent remediation for all organizations running affected Microsoft Windows versions.

CVSS Score

7.6
HIGH(7.6)

EPSS Score

EPSS Score30.34%
EPSS Percentile98.1%

Dates

PublishedFebruary 13, 2024
Last ModifiedAugust 10, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.