New Windows SmartScreen bypass exploited as zero-day since March

Teilen:

Today, Microsoft revealed that a Mark of the Web security bypass vulnerability exploited by attackers as a zero-day to bypass SmartScreen protection was patched during the June 2024 Patch Tuesday.

SmartScreen is a security feature introduced with Windows 8 that protects users against potentially malicious software when opening downloaded files tagged with a Mark of the Web (MotW) label.

While the vulnerability (tracked as CVE-2024-38213) can be exploited remotely by unauthenticated threat actors in low-complexity attacks, it requires user interaction, making successful exploitation harder to achieve.

“An attacker who successfully exploited this vulnerability could bypass the SmartScreen user experience. An attacker must send the user a malicious file and convince them to open it,” Redmond explains in a security advisory published on Tuesday.

Despite the increased difficulty in exploiting it, Trend Micro security researcher Peter Girnus discovered that the vulnerability was being exploited in the wild in March. Girnus reported the attacks to Microsoft, who patched the flaw during the June 2024 Patch Tuesday. However, the company forgot to include the advisory with that month’s security updates (or with July’s).

“In March 2024, Trend Micro’s Zero Day Initiative Threat Hunting team started analyzing samples connected to the activity carried out by DarkGate operators to infect users through copy-and-paste operations,” ZDI’s Head of Threat Awareness Dustin Childs told BleepingComputer today.

“This DarkGate campaign was an update from a previous campaign in which the DarkGate operators were exploiting a zero-day vulnerability, CVE-2024-21412, which we disclosed to Microsoft earlier this year.”

Windows SmartScreen abused in malware attacks

In the March attacks, DarkGate malware operators exploited this Windows SmartScreen bypass (CVE-2024-21412) to deploy malicious payloads camouflaged as installers for Apple iTunes, Notion, NVIDIA, and other legitimate software.

While investigating the March campaign, Trend Micro’s researchers also looked into SmartScreen abuse in attacks and how files from WebDAV shares were handled during copy-and-paste operations.

“As a result, we discovered and reported CVE-2024-38213 to Microsoft, which they patched in June. This exploit, which we’ve named copy2pwn, results in a file from a WebDAV being copied locally without Mark-of-the-Web protections,” Childs added.

CVE-2024-21412 was itself a bypass for another Defender SmartScreen vulnerability tracked as CVE-2023-36025, exploited as a zero-day to deploy Phemedrone malware and patched during the November 2023 Patch Tuesday.

Since the start of the year, the financially motivated Water Hydra (aka DarkCasino) hacking group has also exploited CVE-2024-21412 to target stock trading Telegram channels and forex trading forums with the DarkMe remote access trojan (RAT) on New Year’s Eve.

Childs also told BleepingComputer in April that the same cybercrime gang exploited CVE-2024-29988 (another SmartScreen flaw and a CVE-2024-21412 bypass) in February malware attacks.

Furthermore, as Elastic Security Labs discovered, a design flaw in Windows Smart App Control and SmartScreen enabling attackers to launch programs without triggering security warnings has also been exploited in attacks since at least 2018. Elastic Security Labs reported these findings to Microsoft and was told that this issue “may be fixed” in a future Windows update.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
4:22 am, März 17, 2025
Wetter-Symbol 6°C
L: 5° | H: 6°
light rain
Luftfeuchtigkeit: 81 %
Druck: 1028 mb
Wind: 6 mph E
Windböe: 12 mph
UV-Index: 0
Niederschlag: 0.11 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 6:09 am
Sonnenuntergang: 6:07 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
5° | 6°°C 0 mm 0% 10 mph 82 % 1028 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
3° | 9°°C 0 mm 0% 12 mph 69 % 1027 mb 0 mm/h
Mi. März 19 9:00 pm
Wetter-Symbol
3° | 15°°C 0 mm 0% 6 mph 82 % 1022 mb 0 mm/h
Do. März 20 9:00 pm
Wetter-Symbol
8° | 16°°C 0 mm 0% 8 mph 74 % 1021 mb 0 mm/h
Fr. März 21 9:00 pm
Wetter-Symbol
9° | 13°°C 0.2 mm 20% 6 mph 93 % 1015 mb 0 mm/h
Today 6:00 am
Wetter-Symbol
3° | 5°°C 0 mm 0% 7 mph 82 % 1027 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
6° | 6°°C 0 mm 0% 10 mph 69 % 1028 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
8° | 8°°C 0 mm 0% 10 mph 55 % 1028 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
8° | 8°°C 0 mm 0% 10 mph 56 % 1027 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 10 mph 73 % 1028 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 9 mph 76 % 1028 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 9 mph 67 % 1027 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 7 mph 69 % 1026 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€76,961.83
-0.74%
Ethereum(ETH)
€1,754.37
-0.98%
Fesseln(USDT)
€0.92
-0.01%
XRP(XRP)
€2.17
-1.23%
Solana(SOL)
€118.54
-4.85%
USDC(USDC)
€0.92
0.00%
Dogecoin(DOGE)
€0.158914
-1.03%
Shiba Inu(SHIB)
€0.000012
3.97%
Pepe(PEPE)
€0.000006
-4.62%
Peanut das Eichhörnchen(PNUT)
€0.189641
20.47%
Nach oben scrollen