Mark of the Web (MoTW) Bypass Vulnerability
ID: bdea492f-00d3-55e0-a420-e03fade7917f
STIX ID: report--bdea492f-00d3-55e0-a420-e03fade7917f
Feed Name: ASEC
This report explains how Windows' Mark of the Web (MoTW) can be bypassed and documents multiple related vulnerabilities and exploitation techniques — including a 7‑Zip double-compression flaw (CVE‑2025‑0411) exploited in a zero‑day campaign, LNK stomping (CVE‑2024‑38217), and a WebDAV copy handling issue (CVE‑2024‑38213) — which threat actors have used to deliver malware such as SmokeLoader and LummaStealer and evade security warnings; it recommends applying updates and using security controls to validate file origins.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
