logo

New Windows SmartScreen bypass exploited as zero-day since March

ID: 5e2cfbd4-d30a-5fed-8d8c-35faf6094711

STIX ID: report--5e2cfbd4-d30a-5fed-8d8c-35faf6094711

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-08-13

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft patched a SmartScreen Mark-of-the-Web bypass (CVE-2024-38213, aka "copy2pwn") in June 2024 after Trend Micro / ZDI found it exploited in the wild to strip MotW protections from files (notably when copying from WebDAV), enabling malware delivery (DarkGate/DarkMe) by financially motivated cybercrime groups; the flaw required user interaction but was actively abused prior to the patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.