logo

Windows Smart App Control, SmartScreen bypass exploited since 2018

ID: 8249f3db-03ec-5bcf-895e-3a84e25c2131

STIX ID: report--8249f3db-03ec-5bcf-895e-3a84e25c2131

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-08-05

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

Elastic Security Labs disclosed a Windows design flaw in Smart App Control and SmartScreen that attackers can abuse by crafting LNK files ('LNK stomping') which cause Explorer to canonicalize paths, remove the Mark of the Web, and launch untrusted executables without security warnings; multiple historical samples were found on VirusTotal, detection guidance and a checking tool were released, and Microsoft was notified about a potential future patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.